{"cves":[{"id":"CVE-2026-44185","published":"2026-06-08T16:16:00","updated_at":"2026-07-20T23:10:54.896836+00:00","description":"\nBuffer Over-read vulnerability in Apache HTTP Server via outbound OCSP\nrequests to an attacker controlled OCSP server\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44185","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44185","https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/06/08/12","https://ubuntu.com/security/notices/USN-8516-1","https://ubuntu.com/security/notices/USN-8571-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139340"],"patches":{"apache2":["upstream: https://github.com/apache/httpd/commit/32b7e2e66477020ba75b78ab43fb8890ec292ad2"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"noble","status":"released","description":"2.4.58-1ubuntu8.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.66-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.27+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.23+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm19","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"upstream","status":"released","description":"2.4.68","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu4.23","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-8516-1","USN-8571-1"],"notices":[{"id":"USN-8516-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T13:49:49.469073","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. An attacker\ncould use this issue to cause the server to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause Apache HTTP Server to crash, resulting in\na denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker with\n.htaccess write access could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause Apache\nHTTP Server to stop responding, resulting in a denial of service.\n(CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could possibly\nuse this issue to execute arbitrary code or cause a denial of service.\n(CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-48913)","is_hidden":false,"release_packages":{"jammy":[{"name":"apache2","version":"2.4.52-1ubuntu4.23","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-bin","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-data","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-doc","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-utils","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"}],"noble":[{"name":"apache2","version":"2.4.58-1ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-data","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"}],"resolute":[{"name":"apache2","version":"2.4.66-2ubuntu2.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-data","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44119","CVE-2026-48913","CVE-2026-44631","CVE-2026-42536","CVE-2026-34355","CVE-2026-29170","CVE-2026-29167","CVE-2026-44186","CVE-2026-42535","CVE-2026-43951","CVE-2026-44185","CVE-2026-34356"]},{"id":"USN-8571-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T19:03:33.143152","description":"Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server\nincorrectly handled certain memory operations in mod_authn_socache. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-33007)\n\nHaruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache\nHTTP Server had an HTTP response splitting vulnerability in multiple\nmodules when used with untrusted or compromised backend servers. An\nattacker could possibly use this issue to inject arbitrary HTTP headers.\n(CVE-2026-33523)\n\nElhanan Haenel discovered that Apache HTTP Server incorrectly handled\ncertain memory operations in mod_proxy_ajp. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-33857)\n\nTianshuo Han and Jérôme Djouder discovered that Apache HTTP Server\nincorrectly handled certain string operations in mod_proxy_ajp. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-34032)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker\nwith .htaccess write access could possibly use this issue to obtain\nsensitive information. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could\npossibly use this issue to execute arbitrary code or cause a denial of\nservice. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and\nUbuntu 20.04 LTS. (CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)","is_hidden":false,"release_packages":{"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-34032","CVE-2026-33523","CVE-2026-42536","CVE-2026-43951","CVE-2026-34356","CVE-2026-34355","CVE-2026-33857","CVE-2026-44631","CVE-2026-48913","CVE-2026-44186","CVE-2026-49975","CVE-2026-42535","CVE-2026-44185","CVE-2026-44119","CVE-2026-33007"]}]},{"id":"CVE-2026-44119","published":"2026-06-08T16:16:00","updated_at":"2026-07-20T23:10:54.896836+00:00","description":"\nImproper Privilege Management vulnerability in Apache HTTP Server 2.4.67\nand earlier allows local .htaccess authors to read files with the\nprivileges of the httpd user.\nThis issue affects Apache HTTP Server: from through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44119","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44119","https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/06/08/11","https://ubuntu.com/security/notices/USN-8516-1","https://ubuntu.com/security/notices/USN-8571-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139340"],"patches":{"apache2":["upstream: https://github.com/apache/httpd/commit/f63f26aff6aa747357b84b5bd09c45325fa7f9ba"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.27+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.23+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm19","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"upstream","status":"released","description":"2.4.68","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu4.23","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.58-1ubuntu8.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.66-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-8516-1","USN-8571-1"],"notices":[{"id":"USN-8516-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T13:49:49.469073","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. An attacker\ncould use this issue to cause the server to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause Apache HTTP Server to crash, resulting in\na denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker with\n.htaccess write access could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause Apache\nHTTP Server to stop responding, resulting in a denial of service.\n(CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could possibly\nuse this issue to execute arbitrary code or cause a denial of service.\n(CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-48913)","is_hidden":false,"release_packages":{"jammy":[{"name":"apache2","version":"2.4.52-1ubuntu4.23","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-bin","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-data","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-doc","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-utils","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"}],"noble":[{"name":"apache2","version":"2.4.58-1ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-data","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"}],"resolute":[{"name":"apache2","version":"2.4.66-2ubuntu2.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-data","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44119","CVE-2026-48913","CVE-2026-44631","CVE-2026-42536","CVE-2026-34355","CVE-2026-29170","CVE-2026-29167","CVE-2026-44186","CVE-2026-42535","CVE-2026-43951","CVE-2026-44185","CVE-2026-34356"]},{"id":"USN-8571-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T19:03:33.143152","description":"Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server\nincorrectly handled certain memory operations in mod_authn_socache. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-33007)\n\nHaruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache\nHTTP Server had an HTTP response splitting vulnerability in multiple\nmodules when used with untrusted or compromised backend servers. An\nattacker could possibly use this issue to inject arbitrary HTTP headers.\n(CVE-2026-33523)\n\nElhanan Haenel discovered that Apache HTTP Server incorrectly handled\ncertain memory operations in mod_proxy_ajp. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-33857)\n\nTianshuo Han and Jérôme Djouder discovered that Apache HTTP Server\nincorrectly handled certain string operations in mod_proxy_ajp. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-34032)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker\nwith .htaccess write access could possibly use this issue to obtain\nsensitive information. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could\npossibly use this issue to execute arbitrary code or cause a denial of\nservice. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and\nUbuntu 20.04 LTS. (CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)","is_hidden":false,"release_packages":{"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-34032","CVE-2026-33523","CVE-2026-42536","CVE-2026-43951","CVE-2026-34356","CVE-2026-34355","CVE-2026-33857","CVE-2026-44631","CVE-2026-48913","CVE-2026-44186","CVE-2026-49975","CVE-2026-42535","CVE-2026-44185","CVE-2026-44119","CVE-2026-33007"]}]},{"id":"CVE-2026-43951","published":"2026-06-08T16:16:00","updated_at":"2026-07-20T23:10:54.896836+00:00","description":"\nOut-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and\nmod_mime and multiple response languages.\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43951","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-43951","https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/06/08/10","https://ubuntu.com/security/notices/USN-8516-1","https://ubuntu.com/security/notices/USN-8571-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139340"],"patches":{"apache2":["upstream: https://github.com/apache/httpd/commit/6ff9dc2fdbe7ffd2f8a6c9ffe9ec801d53c760ba"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm19","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"upstream","status":"released","description":"2.4.68","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu4.23","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.58-1ubuntu8.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.66-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.27+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.23+esm5","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8516-1","USN-8571-1"],"notices":[{"id":"USN-8516-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T13:49:49.469073","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. An attacker\ncould use this issue to cause the server to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause Apache HTTP Server to crash, resulting in\na denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker with\n.htaccess write access could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause Apache\nHTTP Server to stop responding, resulting in a denial of service.\n(CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could possibly\nuse this issue to execute arbitrary code or cause a denial of service.\n(CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-48913)","is_hidden":false,"release_packages":{"jammy":[{"name":"apache2","version":"2.4.52-1ubuntu4.23","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-bin","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-data","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-doc","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-utils","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"}],"noble":[{"name":"apache2","version":"2.4.58-1ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-data","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"}],"resolute":[{"name":"apache2","version":"2.4.66-2ubuntu2.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-data","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44119","CVE-2026-48913","CVE-2026-44631","CVE-2026-42536","CVE-2026-34355","CVE-2026-29170","CVE-2026-29167","CVE-2026-44186","CVE-2026-42535","CVE-2026-43951","CVE-2026-44185","CVE-2026-34356"]},{"id":"USN-8571-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T19:03:33.143152","description":"Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server\nincorrectly handled certain memory operations in mod_authn_socache. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-33007)\n\nHaruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache\nHTTP Server had an HTTP response splitting vulnerability in multiple\nmodules when used with untrusted or compromised backend servers. An\nattacker could possibly use this issue to inject arbitrary HTTP headers.\n(CVE-2026-33523)\n\nElhanan Haenel discovered that Apache HTTP Server incorrectly handled\ncertain memory operations in mod_proxy_ajp. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-33857)\n\nTianshuo Han and Jérôme Djouder discovered that Apache HTTP Server\nincorrectly handled certain string operations in mod_proxy_ajp. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-34032)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker\nwith .htaccess write access could possibly use this issue to obtain\nsensitive information. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could\npossibly use this issue to execute arbitrary code or cause a denial of\nservice. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and\nUbuntu 20.04 LTS. (CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)","is_hidden":false,"release_packages":{"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-34032","CVE-2026-33523","CVE-2026-42536","CVE-2026-43951","CVE-2026-34356","CVE-2026-34355","CVE-2026-33857","CVE-2026-44631","CVE-2026-48913","CVE-2026-44186","CVE-2026-49975","CVE-2026-42535","CVE-2026-44185","CVE-2026-44119","CVE-2026-33007"]}]},{"id":"CVE-2026-42536","published":"2026-06-08T16:16:00","updated_at":"2026-07-20T23:10:54.896836+00:00","description":"\nHeap-based Buffer Overflow vulnerability in Apache HTTP Server\nwith mod_xml2enc, xml2StartParse, and untrusted content\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42536","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42536","https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/06/08/9","https://ubuntu.com/security/notices/USN-8516-1","https://ubuntu.com/security/notices/USN-8571-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139340"],"patches":{"apache2":["upstream: https://github.com/apache/httpd/commit/cb1f79c0ce66393c48657b19df754f16b79af543"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"upstream","status":"released","description":"2.4.68","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu4.23","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.58-1ubuntu8.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.66-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.27+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.23+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm19","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8516-1","USN-8571-1"],"notices":[{"id":"USN-8516-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T13:49:49.469073","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. An attacker\ncould use this issue to cause the server to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause Apache HTTP Server to crash, resulting in\na denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker with\n.htaccess write access could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause Apache\nHTTP Server to stop responding, resulting in a denial of service.\n(CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could possibly\nuse this issue to execute arbitrary code or cause a denial of service.\n(CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-48913)","is_hidden":false,"release_packages":{"jammy":[{"name":"apache2","version":"2.4.52-1ubuntu4.23","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-bin","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-data","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-doc","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-utils","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"}],"noble":[{"name":"apache2","version":"2.4.58-1ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-data","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"}],"resolute":[{"name":"apache2","version":"2.4.66-2ubuntu2.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-data","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44119","CVE-2026-48913","CVE-2026-44631","CVE-2026-42536","CVE-2026-34355","CVE-2026-29170","CVE-2026-29167","CVE-2026-44186","CVE-2026-42535","CVE-2026-43951","CVE-2026-44185","CVE-2026-34356"]},{"id":"USN-8571-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T19:03:33.143152","description":"Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server\nincorrectly handled certain memory operations in mod_authn_socache. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-33007)\n\nHaruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache\nHTTP Server had an HTTP response splitting vulnerability in multiple\nmodules when used with untrusted or compromised backend servers. An\nattacker could possibly use this issue to inject arbitrary HTTP headers.\n(CVE-2026-33523)\n\nElhanan Haenel discovered that Apache HTTP Server incorrectly handled\ncertain memory operations in mod_proxy_ajp. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-33857)\n\nTianshuo Han and Jérôme Djouder discovered that Apache HTTP Server\nincorrectly handled certain string operations in mod_proxy_ajp. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-34032)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker\nwith .htaccess write access could possibly use this issue to obtain\nsensitive information. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could\npossibly use this issue to execute arbitrary code or cause a denial of\nservice. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and\nUbuntu 20.04 LTS. (CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)","is_hidden":false,"release_packages":{"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-34032","CVE-2026-33523","CVE-2026-42536","CVE-2026-43951","CVE-2026-34356","CVE-2026-34355","CVE-2026-33857","CVE-2026-44631","CVE-2026-48913","CVE-2026-44186","CVE-2026-49975","CVE-2026-42535","CVE-2026-44185","CVE-2026-44119","CVE-2026-33007"]}]},{"id":"CVE-2026-42535","published":"2026-06-08T16:16:00","updated_at":"2026-07-20T23:10:54.896836+00:00","description":"\nA path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a\nWebDAV content author to directly manipulate trusted DAV property\ndatabases, potentially causing child process crashes.\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42535","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42535","https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/06/08/8","https://ubuntu.com/security/notices/USN-8516-1","https://ubuntu.com/security/notices/USN-8571-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139340"],"patches":{"apache2":["upstream: https://github.com/apache/httpd/commit/56bfb128432a38e2e6bc5448122914bb271b1252"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"upstream","status":"released","description":"2.4.68","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu4.23","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.58-1ubuntu8.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.66-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.27+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.23+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm19","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8516-1","USN-8571-1"],"notices":[{"id":"USN-8516-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T13:49:49.469073","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. An attacker\ncould use this issue to cause the server to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause Apache HTTP Server to crash, resulting in\na denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker with\n.htaccess write access could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause Apache\nHTTP Server to stop responding, resulting in a denial of service.\n(CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could possibly\nuse this issue to execute arbitrary code or cause a denial of service.\n(CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-48913)","is_hidden":false,"release_packages":{"jammy":[{"name":"apache2","version":"2.4.52-1ubuntu4.23","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-bin","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-data","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-doc","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-utils","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"}],"noble":[{"name":"apache2","version":"2.4.58-1ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-data","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"}],"resolute":[{"name":"apache2","version":"2.4.66-2ubuntu2.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-data","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44119","CVE-2026-48913","CVE-2026-44631","CVE-2026-42536","CVE-2026-34355","CVE-2026-29170","CVE-2026-29167","CVE-2026-44186","CVE-2026-42535","CVE-2026-43951","CVE-2026-44185","CVE-2026-34356"]},{"id":"USN-8571-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T19:03:33.143152","description":"Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server\nincorrectly handled certain memory operations in mod_authn_socache. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-33007)\n\nHaruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache\nHTTP Server had an HTTP response splitting vulnerability in multiple\nmodules when used with untrusted or compromised backend servers. An\nattacker could possibly use this issue to inject arbitrary HTTP headers.\n(CVE-2026-33523)\n\nElhanan Haenel discovered that Apache HTTP Server incorrectly handled\ncertain memory operations in mod_proxy_ajp. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-33857)\n\nTianshuo Han and Jérôme Djouder discovered that Apache HTTP Server\nincorrectly handled certain string operations in mod_proxy_ajp. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-34032)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker\nwith .htaccess write access could possibly use this issue to obtain\nsensitive information. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could\npossibly use this issue to execute arbitrary code or cause a denial of\nservice. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and\nUbuntu 20.04 LTS. (CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)","is_hidden":false,"release_packages":{"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-34032","CVE-2026-33523","CVE-2026-42536","CVE-2026-43951","CVE-2026-34356","CVE-2026-34355","CVE-2026-33857","CVE-2026-44631","CVE-2026-48913","CVE-2026-44186","CVE-2026-49975","CVE-2026-42535","CVE-2026-44185","CVE-2026-44119","CVE-2026-33007"]}]},{"id":"CVE-2026-34356","published":"2026-06-08T16:16:00","updated_at":"2026-07-20T23:10:54.896836+00:00","description":"\nHeap-based Buffer Overflow vulnerability in Apache HTTP Server with\nmalicious backend servers and ProxyPassReverseCookie*\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34356","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-34356","https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/06/08/7","https://ubuntu.com/security/notices/USN-8516-1","https://ubuntu.com/security/notices/USN-8571-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139340"],"patches":{"apache2":["upstream: https://github.com/apache/httpd/commit/403269396d24404e2576a9b20f96cd0b10574048"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"upstream","status":"released","description":"2.4.68","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu4.23","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.58-1ubuntu8.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.66-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.27+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.23+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm19","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8516-1","USN-8571-1"],"notices":[{"id":"USN-8516-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T13:49:49.469073","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. An attacker\ncould use this issue to cause the server to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause Apache HTTP Server to crash, resulting in\na denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker with\n.htaccess write access could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause Apache\nHTTP Server to stop responding, resulting in a denial of service.\n(CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could possibly\nuse this issue to execute arbitrary code or cause a denial of service.\n(CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-48913)","is_hidden":false,"release_packages":{"jammy":[{"name":"apache2","version":"2.4.52-1ubuntu4.23","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-bin","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-data","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-doc","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-utils","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"}],"noble":[{"name":"apache2","version":"2.4.58-1ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-data","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"}],"resolute":[{"name":"apache2","version":"2.4.66-2ubuntu2.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-data","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44119","CVE-2026-48913","CVE-2026-44631","CVE-2026-42536","CVE-2026-34355","CVE-2026-29170","CVE-2026-29167","CVE-2026-44186","CVE-2026-42535","CVE-2026-43951","CVE-2026-44185","CVE-2026-34356"]},{"id":"USN-8571-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T19:03:33.143152","description":"Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server\nincorrectly handled certain memory operations in mod_authn_socache. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-33007)\n\nHaruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache\nHTTP Server had an HTTP response splitting vulnerability in multiple\nmodules when used with untrusted or compromised backend servers. An\nattacker could possibly use this issue to inject arbitrary HTTP headers.\n(CVE-2026-33523)\n\nElhanan Haenel discovered that Apache HTTP Server incorrectly handled\ncertain memory operations in mod_proxy_ajp. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-33857)\n\nTianshuo Han and Jérôme Djouder discovered that Apache HTTP Server\nincorrectly handled certain string operations in mod_proxy_ajp. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-34032)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker\nwith .htaccess write access could possibly use this issue to obtain\nsensitive information. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could\npossibly use this issue to execute arbitrary code or cause a denial of\nservice. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and\nUbuntu 20.04 LTS. (CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)","is_hidden":false,"release_packages":{"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-34032","CVE-2026-33523","CVE-2026-42536","CVE-2026-43951","CVE-2026-34356","CVE-2026-34355","CVE-2026-33857","CVE-2026-44631","CVE-2026-48913","CVE-2026-44186","CVE-2026-49975","CVE-2026-42535","CVE-2026-44185","CVE-2026-44119","CVE-2026-33007"]}]},{"id":"CVE-2026-34355","published":"2026-06-08T16:16:00","updated_at":"2026-07-20T23:10:54.896836+00:00","description":"\nA buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and\nearlier allows an attack by an untrusted backend.\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-34355","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-34355","https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/06/08/6","https://ubuntu.com/security/notices/USN-8516-1","https://ubuntu.com/security/notices/USN-8571-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139340"],"patches":{"apache2":["upstream: https://github.com/apache/httpd/commit/d62fc375281486c6036b007ac349b25d4e6edb4a"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"upstream","status":"released","description":"2.4.68","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu4.23","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.58-1ubuntu8.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.66-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.27+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.23+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm14","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm19","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8516-1","USN-8571-1"],"notices":[{"id":"USN-8516-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T13:49:49.469073","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. An attacker\ncould use this issue to cause the server to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause Apache HTTP Server to crash, resulting in\na denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker with\n.htaccess write access could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause Apache\nHTTP Server to stop responding, resulting in a denial of service.\n(CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could possibly\nuse this issue to execute arbitrary code or cause a denial of service.\n(CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-48913)","is_hidden":false,"release_packages":{"jammy":[{"name":"apache2","version":"2.4.52-1ubuntu4.23","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-bin","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-data","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-doc","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-utils","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"}],"noble":[{"name":"apache2","version":"2.4.58-1ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-data","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"}],"resolute":[{"name":"apache2","version":"2.4.66-2ubuntu2.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-data","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44119","CVE-2026-48913","CVE-2026-44631","CVE-2026-42536","CVE-2026-34355","CVE-2026-29170","CVE-2026-29167","CVE-2026-44186","CVE-2026-42535","CVE-2026-43951","CVE-2026-44185","CVE-2026-34356"]},{"id":"USN-8571-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-20T19:03:33.143152","description":"Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server\nincorrectly handled certain memory operations in mod_authn_socache. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-33007)\n\nHaruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache\nHTTP Server had an HTTP response splitting vulnerability in multiple\nmodules when used with untrusted or compromised backend servers. An\nattacker could possibly use this issue to inject arbitrary HTTP headers.\n(CVE-2026-33523)\n\nElhanan Haenel discovered that Apache HTTP Server incorrectly handled\ncertain memory operations in mod_proxy_ajp. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-33857)\n\nTianshuo Han and Jérôme Djouder discovered that Apache HTTP Server\nincorrectly handled certain string operations in mod_proxy_ajp. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-34032)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A\nremote attacker could possibly use this issue to cause a denial of service.\n(CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause a denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker\nwith .htaccess write access could possibly use this issue to obtain\nsensitive information. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could\npossibly use this issue to execute arbitrary code or cause a denial of\nservice. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and\nUbuntu 20.04 LTS. (CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)","is_hidden":false,"release_packages":{"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.27+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.23+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm19","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-34032","CVE-2026-33523","CVE-2026-42536","CVE-2026-43951","CVE-2026-34356","CVE-2026-34355","CVE-2026-33857","CVE-2026-44631","CVE-2026-48913","CVE-2026-44186","CVE-2026-49975","CVE-2026-42535","CVE-2026-44185","CVE-2026-44119","CVE-2026-33007"]}]},{"id":"CVE-2026-29170","published":"2026-06-08T16:16:00","updated_at":"2026-08-06T19:23:52.637150+00:00","description":"\nA cross-site scripting vulnerability exists in mod_proxy_ftp's HTML\ndirectory list generation in Apache HTTP Server 2.4.67 and earlier when\nlisting FTP directory contents either via forward or reverse proxy\nconfiguration.\nUsers are recommended to upgrade to version 2.4.68, which fixes this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-29170","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29170","https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/06/08/5","https://ubuntu.com/security/notices/USN-8516-1","https://ubuntu.com/security/notices/USN-8589-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139340"],"patches":{"apache2":["upstream: https://github.com/apache/httpd/commit/04641bce75a2734ad8150f9a6bc84fc5205e852b"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"upstream","status":"released","description":"2.4.68","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu4.23","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.58-1ubuntu8.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.66-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.27+esm11","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.23+esm6","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm15","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm20","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8516-1","USN-8589-1"],"notices":[{"id":"USN-8516-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T13:49:49.469073","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. An attacker\ncould use this issue to cause the server to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause Apache HTTP Server to crash, resulting in\na denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker with\n.htaccess write access could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause Apache\nHTTP Server to stop responding, resulting in a denial of service.\n(CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could possibly\nuse this issue to execute arbitrary code or cause a denial of service.\n(CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-48913)","is_hidden":false,"release_packages":{"jammy":[{"name":"apache2","version":"2.4.52-1ubuntu4.23","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-bin","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-data","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-doc","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-utils","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"}],"noble":[{"name":"apache2","version":"2.4.58-1ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-data","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"}],"resolute":[{"name":"apache2","version":"2.4.66-2ubuntu2.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-data","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44119","CVE-2026-48913","CVE-2026-44631","CVE-2026-42536","CVE-2026-34355","CVE-2026-29170","CVE-2026-29167","CVE-2026-44186","CVE-2026-42535","CVE-2026-43951","CVE-2026-44185","CVE-2026-34356"]},{"id":"USN-8589-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"After a standard system update you need to restart apache2 to make\nall the necessary changes.","references":[],"published":"2026-07-22T16:41:46.776669","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. A remote\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nNitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module\nwas vulnerable to a timing attack. A remote attacker could possibly use\nthis issue to bypass Digest authentication. (CVE-2026-33006)","is_hidden":false,"release_packages":{"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm11","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm6","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm20","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-29167","CVE-2026-33006","CVE-2026-29170"]}]},{"id":"CVE-2026-29167","published":"2026-06-08T16:16:00","updated_at":"2026-08-06T19:23:52.637150+00:00","description":"\nUse After Free vulnerability in Apache HTTP Server with mod_ldap in\nper-directory configuration\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.\nUsers are recommended to upgrade to version 2.4.68, which fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-29167","https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29167","https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/06/08/4","https://ubuntu.com/security/notices/USN-8516-1","https://ubuntu.com/security/notices/USN-8589-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139340"],"patches":{"apache2":["upstream: https://github.com/apache/httpd/commit/2cf9b3f393633f43746047e779fdf265a1ad8016"]},"tags":{},"packages":[{"name":"apache2","source":"https://ubuntu.com/security/cve?package=apache2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apache2","debian":"https://tracker.debian.org/pkg/apache2","statuses":[{"release_codename":"upstream","status":"released","description":"2.4.68","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.4.52-1ubuntu4.23","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.58-1ubuntu8.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"2.4.66-2ubuntu2.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.4.29-1ubuntu4.27+esm11","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.4.41-4ubuntu3.23+esm6","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"2.4.7-1ubuntu4.22+esm15","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2.4.18-2ubuntu3.17+esm20","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8516-1","USN-8589-1"],"notices":[{"id":"USN-8516-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-08T13:49:49.469073","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. An attacker\ncould use this issue to cause the server to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nIt was discovered that Apache HTTP Server's mod_proxy_html module\nincorrectly handled certain content from an untrusted backend. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34355)\n\nIt was discovered that Apache HTTP Server incorrectly handled\nProxyPassReverseCookie directives with a malicious backend server. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-34356)\n\nIt was discovered that Apache HTTP Server's mod_dav_fs module incorrectly\nhandled certain path operations. An authenticated user could possibly use\nthis issue to manipulate trusted WebDAV property databases or cause a\ndenial of service. (CVE-2026-42535)\n\nIt was discovered that Apache HTTP Server's mod_xml2enc module incorrectly\nhandled certain content from an untrusted backend. A remote attacker could\npossibly use this issue to cause Apache HTTP Server to crash, resulting in\na denial of service. (CVE-2026-42536)\n\nIt was discovered that Apache HTTP Server incorrectly handled response\nheaders when multiple content languages were configured. A remote attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2026-43951)\n\nIt was discovered that Apache HTTP Server incorrectly restricted certain\nfile functions in expressions within .htaccess files. A local attacker with\n.htaccess write access could possibly use this issue to obtain sensitive\ninformation. (CVE-2026-44119)\n\nIt was discovered that Apache HTTP Server's mod_ssl module incorrectly\nhandled OCSP responses from an attacker-controlled server. A remote\nattacker could possibly use this issue to obtain sensitive information or\ncause a denial of service. (CVE-2026-44185)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled responses from an attacker-controlled backend FTP\nserver. A remote attacker could possibly use this issue to cause Apache\nHTTP Server to stop responding, resulting in a denial of service.\n(CVE-2026-44186)\n\nIt was discovered that Apache HTTP Server incorrectly handled crafted\nregular expressions in the server configuration. An attacker could possibly\nuse this issue to execute arbitrary code or cause a denial of service.\n(CVE-2026-44631)\n\nIt was discovered that Apache HTTP Server's mod_http2 module had a\nuse-after-free vulnerability when file handles were exhausted. A remote\nattacker could possibly use this issue to cause Apache HTTP Server to\ncrash, resulting in a denial of service. (CVE-2026-48913)","is_hidden":false,"release_packages":{"jammy":[{"name":"apache2","version":"2.4.52-1ubuntu4.23","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-bin","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-data","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-doc","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"apache2-utils","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.52-1ubuntu4.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23","pocket":"security"}],"noble":[{"name":"apache2","version":"2.4.58-1ubuntu8.15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-bin","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-data","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-doc","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"apache2-utils","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-md","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.58-1ubuntu8.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15","pocket":"security"}],"resolute":[{"name":"apache2","version":"2.4.66-2ubuntu2.4","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-bin","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-data","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-doc","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-ssl-dev","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-custom","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-suexec-pristine","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"},{"name":"apache2-utils","version":"2.4.66-2ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":"https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-44119","CVE-2026-48913","CVE-2026-44631","CVE-2026-42536","CVE-2026-34355","CVE-2026-29170","CVE-2026-29167","CVE-2026-44186","CVE-2026-42535","CVE-2026-43951","CVE-2026-44185","CVE-2026-34356"]},{"id":"USN-8589-1","title":"Apache HTTP Server vulnerabilities","summary":"Several security issues were fixed in Apache HTTP Server.","instructions":"After a standard system update you need to restart apache2 to make\nall the necessary changes.","references":[],"published":"2026-07-22T16:41:46.776669","description":"It was discovered that Apache HTTP Server's mod_ldap module incorrectly\nhandled memory when processing per-directory configurations. A remote\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. (CVE-2026-29167)\n\nIt was discovered that Apache HTTP Server's mod_proxy_ftp module\nincorrectly handled HTML generation for FTP directory listings. A remote\nattacker could possibly use this issue to inject arbitrary web script or\nHTML. (CVE-2026-29170)\n\nNitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module\nwas vulnerable to a timing attack. A remote attacker could possibly use\nthis issue to bypass Digest authentication. (CVE-2026-33006)","is_hidden":false,"release_packages":{"bionic":[{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm11","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.29-1ubuntu4.27+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm6","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-bin","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-data","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-dev","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-doc","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-ssl-dev","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-custom","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-suexec-pristine","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"apache2-utils","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-md","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"},{"name":"libapache2-mod-proxy-uwsgi","version":"2.4.41-4ubuntu3.23+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm15","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-event","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-itk","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-prefork","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-mpm-worker","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2.2-bin","version":"2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-macro","version":"1:2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libapache2-mod-proxy-html","version":"1:2.4.7-1ubuntu4.22+esm15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm20","description":"Apache HTTP server","is_source":true},{"name":"apache2","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-bin","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-data","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-dev","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-doc","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-custom","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-suexec-pristine","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"apache2-utils","version":"2.4.18-2ubuntu3.17+esm20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apache2","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-29167","CVE-2026-33006","CVE-2026-29170"]}]},{"id":"CVE-2025-71315","published":"2026-06-08T16:16:00","updated_at":"2026-09-14T06:45:48.816619+00:00","description":"\nIn the Linux kernel, the following vulnerability has been resolved:\ndrm/vkms: Convert to DRM's vblank timer\nReplace vkms' vblank timer with the DRM implementation. The DRM\ncode is identical in concept, but differs in implementation.\nVblank timers are covered in vblank helpers and initializer macros,\nso remove the corresponding hrtimer in struct vkms_output. The\nvblank timer calls vkms' custom timeout code via handle_vblank_timeout\nin struct drm_crtc_helper_funcs.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nSee ubuntu cvss score"}],"codename":null,"priority":"high","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-71315","https://git.kernel.org/linus/02e2681ffe1addde1fc8c35d05657b16bfa79613 (6.19-rc1)","https://git.kernel.org/stable/c/02e2681ffe1addde1fc8c35d05657b16bfa79613","https://git.kernel.org/stable/c/a0582cc923985c6b72fe871b5f7aa7c682bfc230"],"bugs":[""],"patches":{"linux":["break-fix: 3a0709928b172a4123a76078f70e0a706265690c 02e2681ffe1addde1fc8c35d05657b16bfa79613"],"linux-hwe":[],"linux-hwe-5.4":[],"linux-hwe-5.8":[],"linux-hwe-5.11":[],"linux-hwe-5.13":[],"linux-hwe-5.15":[],"linux-hwe-5.19":[],"linux-hwe-6.2":[],"linux-hwe-6.5":[],"linux-hwe-6.8":[],"linux-hwe-6.11":[],"linux-hwe-6.14":[],"linux-hwe-6.17":[],"linux-hwe-edge":[],"linux-lts-xenial":[],"linux-kvm":[],"linux-allwinner-5.19":[],"linux-aws":[],"linux-aws-5.0":[],"linux-aws-5.3":[],"linux-aws-5.4":[],"linux-aws-5.8":[],"linux-aws-5.11":[],"linux-aws-5.13":[],"linux-aws-5.15":[],"linux-aws-5.19":[],"linux-aws-6.2":[],"linux-aws-6.5":[],"linux-aws-6.8":[],"linux-aws-6.14":[],"linux-aws-6.17":[],"linux-aws-hwe":[],"linux-azure":[],"linux-azure-4.15":[],"linux-azure-5.3":[],"linux-azure-5.4":[],"linux-azure-5.8":[],"linux-azure-5.11":[],"linux-azure-5.13":[],"linux-azure-5.15":[],"linux-azure-5.19":[],"linux-azure-6.2":[],"linux-azure-6.5":[],"linux-azure-6.8":[],"linux-azure-6.11":[],"linux-azure-6.14":[],"linux-azure-6.17":[],"linux-azure-fde":[],"linux-azure-fde-5.15":[],"linux-azure-fde-5.19":[],"linux-azure-fde-6.2":[],"linux-azure-fde-6.8":[],"linux-azure-fde-6.14":[],"linux-azure-fde-6.17":[],"linux-azure-nvidia":[],"linux-azure-nvidia-6.14":[],"linux-bluefield":[],"linux-azure-edge":[],"linux-fips":[],"linux-aws-fips":[],"linux-azure-fips":[],"linux-gcp-fips":[],"linux-gcp":[],"linux-gcp-4.15":[],"linux-gcp-5.3":[],"linux-gcp-5.4":[],"linux-gcp-5.8":[],"linux-gcp-5.11":[],"linux-gcp-5.13":[],"linux-gcp-5.15":[],"linux-gcp-5.19":[],"linux-gcp-6.2":[],"linux-gcp-6.5":[],"linux-gcp-6.8":[],"linux-gcp-6.11":[],"linux-gcp-6.14":[],"linux-gcp-6.17":[],"linux-gke":[],"linux-gke-4.15":[],"linux-gke-5.4":[],"linux-gke-5.15":[],"linux-gkeop":[],"linux-gkeop-5.4":[],"linux-gkeop-5.15":[],"linux-ibm":[],"linux-ibm-5.4":[],"linux-ibm-5.15":[],"linux-ibm-6.8":[],"linux-intel-5.13":[],"linux-intel-iotg":[],"linux-intel-iotg-5.15":[],"linux-iot":[],"linux-intel-iot-realtime":[],"linux-lowlatency":[],"linux-lowlatency-hwe-5.15":[],"linux-lowlatency-hwe-5.19":[],"linux-lowlatency-hwe-6.2":[],"linux-lowlatency-hwe-6.5":[],"linux-lowlatency-hwe-6.8":[],"linux-lowlatency-hwe-6.11":[],"linux-nvidia":[],"linux-nvidia-6.2":[],"linux-nvidia-6.5":[],"linux-nvidia-6.8":[],"linux-nvidia-6.11":[],"linux-nvidia-6.17":[],"linux-nvidia-lowlatency":[],"linux-nvidia-tegra":[],"linux-nvidia-tegra-5.15":[],"linux-nvidia-tegra-igx":[],"linux-oracle":[],"linux-oracle-5.0":[],"linux-oracle-5.3":[],"linux-oracle-5.4":[],"linux-oracle-5.8":[],"linux-oracle-5.11":[],"linux-oracle-5.13":[],"linux-oracle-5.15":[],"linux-oracle-6.5":[],"linux-oracle-6.8":[],"linux-oracle-6.14":[],"linux-oracle-6.17":[],"linux-oem":[],"linux-oem-5.6":[],"linux-oem-5.10":[],"linux-oem-5.13":[],"linux-oem-5.14":[],"linux-oem-5.17":[],"linux-oem-6.0":[],"linux-oem-6.1":[],"linux-oem-6.5":[],"linux-oem-6.8":[],"linux-oem-6.11":[],"linux-oem-6.14":[],"linux-oem-6.17":[],"linux-raspi":[],"linux-raspi2":[],"linux-raspi-5.4":[],"linux-raspi-realtime":[],"linux-realtime":[],"linux-realtime-6.8":[],"linux-realtime-6.14":[],"linux-riscv":[],"linux-riscv-5.8":[],"linux-riscv-5.11":[],"linux-riscv-5.15":[],"linux-riscv-5.19":[],"linux-riscv-6.5":[],"linux-riscv-6.8":[],"linux-riscv-6.14":[],"linux-riscv-6.17":[],"linux-starfive-5.19":[],"linux-starfive-6.2":[],"linux-starfive-6.5":[],"linux-xilinx":[],"linux-xilinx-zynqmp":[],"linux-realtime-6.17":[],"linux-hwe-7.0":[],"linux-oem-7.0":[],"linux-nvidia-7.0":[],"linux-nvidia-bos":[],"linux-aws-7.0":[],"linux-riscv-7.0":[],"linux-azure-7.0":[],"linux-azure-fde-7.0":[],"linux-gcp-7.0":[],"linux-oracle-7.0":[]},"tags":{"linux":["kernel-team-severity-assessed-agent","binary-exclude:linux-libc-dev","kernel-team-break-fix-verified-agent"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-16.19","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.19.0-3.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-2.16","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-39.42~16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.8","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.8","debian":"https://tracker.debian.org/pkg/linux-hwe-5.8","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-hwe-5.11","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.11","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.11","debian":"https://tracker.debian.org/pkg/linux-hwe-5.11","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-hwe-5.13","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.13","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.13","debian":"https://tracker.debian.org/pkg/linux-hwe-5.13","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-hwe-5.15","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-hwe-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.19","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.19","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.19","debian":"https://tracker.debian.org/pkg/linux-hwe-5.19","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-hwe-6.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-hwe-6.2","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.2","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.2","debian":"https://tracker.debian.org/pkg/linux-hwe-6.2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-hwe-6.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-hwe-6.5","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.5","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.5","debian":"https://tracker.debian.org/pkg/linux-hwe-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-hwe-6.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-hwe-6.8","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-hwe-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-hwe-6.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-hwe-6.14","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.14","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.14","debian":"https://tracker.debian.org/pkg/linux-hwe-6.14","statuses":[{"release_codename":"noble","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.17","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.17","debian":"https://tracker.debian.org/pkg/linux-hwe-6.17","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1007.12","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-allwinner-5.19","source":"https://ubuntu.com/security/cve?package=linux-allwinner-5.19","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-allwinner-5.19","debian":"https://tracker.debian.org/pkg/linux-allwinner-5.19","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.19.0-1002.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"}]},{"name":"linux-aws-5.0","source":"https://ubuntu.com/security/cve?package=linux-aws-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.0","debian":"https://tracker.debian.org/pkg/linux-aws-5.0","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-aws-5.3","component":null,"pocket":"security"}]},{"name":"linux-aws-5.3","source":"https://ubuntu.com/security/cve?package=linux-aws-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.3","debian":"https://tracker.debian.org/pkg/linux-aws-5.3","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-aws-5.4","component":null,"pocket":"security"}]},{"name":"linux-aws-5.4","source":"https://ubuntu.com/security/cve?package=linux-aws-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.4","debian":"https://tracker.debian.org/pkg/linux-aws-5.4","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-5.8","source":"https://ubuntu.com/security/cve?package=linux-aws-5.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.8","debian":"https://tracker.debian.org/pkg/linux-aws-5.8","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-aws-5.11","component":null,"pocket":"security"}]},{"name":"linux-aws-5.11","source":"https://ubuntu.com/security/cve?package=linux-aws-5.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.11","debian":"https://tracker.debian.org/pkg/linux-aws-5.11","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-aws-5.13","component":null,"pocket":"security"}]},{"name":"linux-aws-5.13","source":"https://ubuntu.com/security/cve?package=linux-aws-5.13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.13","debian":"https://tracker.debian.org/pkg/linux-aws-5.13","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-aws-5.15","component":null,"pocket":"security"}]},{"name":"linux-aws-5.15","source":"https://ubuntu.com/security/cve?package=linux-aws-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.15","debian":"https://tracker.debian.org/pkg/linux-aws-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-5.19","source":"https://ubuntu.com/security/cve?package=linux-aws-5.19","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.19","debian":"https://tracker.debian.org/pkg/linux-aws-5.19","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-aws-6.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-aws-6.2","component":null,"pocket":"security"}]},{"name":"linux-aws-6.2","source":"https://ubuntu.com/security/cve?package=linux-aws-6.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.2","debian":"https://tracker.debian.org/pkg/linux-aws-6.2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-aws-6.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-aws-6.5","component":null,"pocket":"security"}]},{"name":"linux-aws-6.5","source":"https://ubuntu.com/security/cve?package=linux-aws-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.5","debian":"https://tracker.debian.org/pkg/linux-aws-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-aws-6.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-aws-6.8","component":null,"pocket":"security"}]},{"name":"linux-aws-6.8","source":"https://ubuntu.com/security/cve?package=linux-aws-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.8","debian":"https://tracker.debian.org/pkg/linux-aws-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-6.14","source":"https://ubuntu.com/security/cve?package=linux-aws-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.14","debian":"https://tracker.debian.org/pkg/linux-aws-6.14","statuses":[{"release_codename":"noble","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-6.17","source":"https://ubuntu.com/security/cve?package=linux-aws-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.17","debian":"https://tracker.debian.org/pkg/linux-aws-6.17","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1031.33~16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.19.0-1001.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.11.0-1015.15","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1082.92","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.3","source":"https://ubuntu.com/security/cve?package=linux-azure-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.3","debian":"https://tracker.debian.org/pkg/linux-azure-5.3","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-5.4","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.8","source":"https://ubuntu.com/security/cve?package=linux-azure-5.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.8","debian":"https://tracker.debian.org/pkg/linux-azure-5.8","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-5.11","component":null,"pocket":"security"}]},{"name":"linux-azure-5.11","source":"https://ubuntu.com/security/cve?package=linux-azure-5.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.11","debian":"https://tracker.debian.org/pkg/linux-azure-5.11","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-5.13","component":null,"pocket":"security"}]},{"name":"linux-azure-5.13","source":"https://ubuntu.com/security/cve?package=linux-azure-5.13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.13","debian":"https://tracker.debian.org/pkg/linux-azure-5.13","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-5.15","component":null,"pocket":"security"}]},{"name":"linux-azure-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.19","source":"https://ubuntu.com/security/cve?package=linux-azure-5.19","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.19","debian":"https://tracker.debian.org/pkg/linux-azure-5.19","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-azure-6.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-6.2","component":null,"pocket":"security"}]},{"name":"linux-azure-6.2","source":"https://ubuntu.com/security/cve?package=linux-azure-6.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.2","debian":"https://tracker.debian.org/pkg/linux-azure-6.2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-azure-6.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-6.5","component":null,"pocket":"security"}]},{"name":"linux-azure-6.5","source":"https://ubuntu.com/security/cve?package=linux-azure-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.5","debian":"https://tracker.debian.org/pkg/linux-azure-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-azure-6.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-6.8","component":null,"pocket":"security"}]},{"name":"linux-azure-6.8","source":"https://ubuntu.com/security/cve?package=linux-azure-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.8","debian":"https://tracker.debian.org/pkg/linux-azure-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-6.11","source":"https://ubuntu.com/security/cve?package=linux-azure-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.11","debian":"https://tracker.debian.org/pkg/linux-azure-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-azure-6.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-6.14","component":null,"pocket":"security"}]},{"name":"linux-azure-6.14","source":"https://ubuntu.com/security/cve?package=linux-azure-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.14","debian":"https://tracker.debian.org/pkg/linux-azure-6.14","statuses":[{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-6.17","source":"https://ubuntu.com/security/cve?package=linux-azure-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.17","debian":"https://tracker.debian.org/pkg/linux-azure-6.17","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde","source":"https://ubuntu.com/security/cve?package=linux-azure-fde","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde","debian":"https://tracker.debian.org/pkg/linux-azure-fde","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-fde-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-5.19","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-5.19","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-5.19","debian":"https://tracker.debian.org/pkg/linux-azure-fde-5.19","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-azure-fde-6.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-fde-6.2","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-6.2","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-6.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-6.2","debian":"https://tracker.debian.org/pkg/linux-azure-fde-6.2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"replaced by linux-azure-6.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"replaced by linux-azure-6.5","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-6.8","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-6.8","debian":"https://tracker.debian.org/pkg/linux-azure-fde-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-6.14","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-6.14","debian":"https://tracker.debian.org/pkg/linux-azure-fde-6.14","statuses":[{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-6.17","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-6.17","debian":"https://tracker.debian.org/pkg/linux-azure-fde-6.17","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-nvidia","source":"https://ubuntu.com/security/cve?package=linux-azure-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-nvidia","debian":"https://tracker.debian.org/pkg/linux-azure-nvidia","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-nvidia-6.14","source":"https://ubuntu.com/security/cve?package=linux-azure-nvidia-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-nvidia-6.14","debian":"https://tracker.debian.org/pkg/linux-azure-nvidia-6.14","statuses":[{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-bluefield","source":"https://ubuntu.com/security/cve?package=linux-bluefield","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-bluefield","debian":"https://tracker.debian.org/pkg/linux-bluefield","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-azure-5.3","component":null,"pocket":"security"}]},{"name":"linux-fips","source":"https://ubuntu.com/security/cve?package=linux-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fips","debian":"https://tracker.debian.org/pkg/linux-fips","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1011.12","component":null,"pocket":"fips"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"fips"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.1","component":null,"pocket":"fips"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-fips","source":"https://ubuntu.com/security/cve?package=linux-aws-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-fips","debian":"https://tracker.debian.org/pkg/linux-aws-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-2000.4","component":null,"pocket":"fips"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"fips"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fips","source":"https://ubuntu.com/security/cve?package=linux-azure-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fips","debian":"https://tracker.debian.org/pkg/linux-azure-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"fips"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"fips"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-fips","source":"https://ubuntu.com/security/cve?package=linux-gcp-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-fips","debian":"https://tracker.debian.org/pkg/linux-gcp-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"fips"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"fips"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.19.0-1001.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.10.0-1004.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1071.81","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.3","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.3","debian":"https://tracker.debian.org/pkg/linux-gcp-5.3","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-gcp-5.4","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.4","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.4","debian":"https://tracker.debian.org/pkg/linux-gcp-5.4","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.8","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.8","debian":"https://tracker.debian.org/pkg/linux-gcp-5.8","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-gcp-5.11","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.11","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.11","debian":"https://tracker.debian.org/pkg/linux-gcp-5.11","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-gcp-5.13","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.13","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.13","debian":"https://tracker.debian.org/pkg/linux-gcp-5.13","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-gcp-5.15","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.15","debian":"https://tracker.debian.org/pkg/linux-gcp-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.19","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.19","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.19","debian":"https://tracker.debian.org/pkg/linux-gcp-5.19","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-gcp-6.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-gcp-6.2","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.2","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.2","debian":"https://tracker.debian.org/pkg/linux-gcp-6.2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-gcp-6.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-gcp-6.5","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.5","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.5","debian":"https://tracker.debian.org/pkg/linux-gcp-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-gcp-6.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-gcp-6.8","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.8","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.8","debian":"https://tracker.debian.org/pkg/linux-gcp-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.11","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.11","debian":"https://tracker.debian.org/pkg/linux-gcp-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-gcp-6.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-gcp-6.14","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.14","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.14","debian":"https://tracker.debian.org/pkg/linux-gcp-6.14","statuses":[{"release_codename":"noble","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.17","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.17","debian":"https://tracker.debian.org/pkg/linux-gcp-6.17","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"resolute","status":"not-affected","description":"7.0.0-1002.3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke-4.15","source":"https://ubuntu.com/security/cve?package=linux-gke-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke-4.15","debian":"https://tracker.debian.org/pkg/linux-gke-4.15","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-gke-5.0","component":null,"pocket":"security"}]},{"name":"linux-gke-5.4","source":"https://ubuntu.com/security/cve?package=linux-gke-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke-5.4","debian":"https://tracker.debian.org/pkg/linux-gke-5.4","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-gke-5.15","source":"https://ubuntu.com/security/cve?package=linux-gke-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke-5.15","debian":"https://tracker.debian.org/pkg/linux-gke-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-gkeop","source":"https://ubuntu.com/security/cve?package=linux-gkeop","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop","debian":"https://tracker.debian.org/pkg/linux-gkeop","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop-5.4","source":"https://ubuntu.com/security/cve?package=linux-gkeop-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop-5.4","debian":"https://tracker.debian.org/pkg/linux-gkeop-5.4","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-gkeop-5.15","source":"https://ubuntu.com/security/cve?package=linux-gkeop-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop-5.15","debian":"https://tracker.debian.org/pkg/linux-gkeop-5.15","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm","source":"https://ubuntu.com/security/cve?package=linux-ibm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm","debian":"https://tracker.debian.org/pkg/linux-ibm","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.19.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.4","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.4","debian":"https://tracker.debian.org/pkg/linux-ibm-5.4","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.15","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.15","debian":"https://tracker.debian.org/pkg/linux-ibm-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-6.8","source":"https://ubuntu.com/security/cve?package=linux-ibm-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-6.8","debian":"https://tracker.debian.org/pkg/linux-ibm-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-5.13","source":"https://ubuntu.com/security/cve?package=linux-intel-5.13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-5.13","debian":"https://tracker.debian.org/pkg/linux-intel-5.13","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg","debian":"https://tracker.debian.org/pkg/linux-intel-iotg","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg-5.15","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg-5.15","debian":"https://tracker.debian.org/pkg/linux-intel-iotg-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-iot","source":"https://ubuntu.com/security/cve?package=linux-iot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-iot","debian":"https://tracker.debian.org/pkg/linux-iot","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iot-realtime","source":"https://ubuntu.com/security/cve?package=linux-intel-iot-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iot-realtime","debian":"https://tracker.debian.org/pkg/linux-intel-iot-realtime","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency","debian":"https://tracker.debian.org/pkg/linux-lowlatency","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-5.19","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-5.19","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-5.19","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-5.19","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-lowlatency-hwe-6.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-lowlatency-hwe-6.2","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.2","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.2","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-lowlatency-hwe-6.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-lowlatency-hwe-6.5","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.5","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.5","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-lowlatency-hwe-6.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-lowlatency-hwe-6.8","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"replaced by linux-hwe-6.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"replaced by linux-hwe-6.14","component":null,"pocket":"security"}]},{"name":"linux-nvidia","source":"https://ubuntu.com/security/cve?package=linux-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia","debian":"https://tracker.debian.org/pkg/linux-nvidia","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"7.0.0-1005.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.2","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.2","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-nvidia-6.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-nvidia-6.5","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.5","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.5","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-nvidia-6.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-nvidia-6.8","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.8","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.8","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.11","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.11","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.17","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.17","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.17","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-nvidia-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-lowlatency","debian":"https://tracker.debian.org/pkg/linux-nvidia-lowlatency","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-5.15","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-5.15","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-igx","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-igx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-igx","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-igx","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1008.10","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.19.0-1001.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1008.10~16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.0","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.0","debian":"https://tracker.debian.org/pkg/linux-oracle-5.0","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oracle-5.3","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.3","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.3","debian":"https://tracker.debian.org/pkg/linux-oracle-5.3","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oracle-5.4","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.4","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.4","debian":"https://tracker.debian.org/pkg/linux-oracle-5.4","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.8","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.8","debian":"https://tracker.debian.org/pkg/linux-oracle-5.8","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oracle-5.11","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.11","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.11","debian":"https://tracker.debian.org/pkg/linux-oracle-5.11","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oracle-5.13","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.13","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.13","debian":"https://tracker.debian.org/pkg/linux-oracle-5.13","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oracle-5.15","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.15","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.15","debian":"https://tracker.debian.org/pkg/linux-oracle-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.5","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.5","debian":"https://tracker.debian.org/pkg/linux-oracle-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-oracle-6.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oracle-6.8","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.8","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.8","debian":"https://tracker.debian.org/pkg/linux-oracle-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.14","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.14","debian":"https://tracker.debian.org/pkg/linux-oracle-6.14","statuses":[{"release_codename":"noble","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.17","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.17","debian":"https://tracker.debian.org/pkg/linux-oracle-6.17","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-oem-5.6","source":"https://ubuntu.com/security/cve?package=linux-oem-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-5.6","debian":"https://tracker.debian.org/pkg/linux-oem-5.6","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oem-5.10","component":null,"pocket":"security"}]},{"name":"linux-oem-5.10","source":"https://ubuntu.com/security/cve?package=linux-oem-5.10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-5.10","debian":"https://tracker.debian.org/pkg/linux-oem-5.10","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oem-5.13","component":null,"pocket":"security"}]},{"name":"linux-oem-5.13","source":"https://ubuntu.com/security/cve?package=linux-oem-5.13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-5.13","debian":"https://tracker.debian.org/pkg/linux-oem-5.13","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oem-5.14","component":null,"pocket":"security"}]},{"name":"linux-oem-5.14","source":"https://ubuntu.com/security/cve?package=linux-oem-5.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-5.14","debian":"https://tracker.debian.org/pkg/linux-oem-5.14","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"replaced by linux-hwe-5.15","component":null,"pocket":"security"}]},{"name":"linux-oem-5.17","source":"https://ubuntu.com/security/cve?package=linux-oem-5.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-5.17","debian":"https://tracker.debian.org/pkg/linux-oem-5.17","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-oem-6.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oem-6.1","component":null,"pocket":"security"}]},{"name":"linux-oem-6.0","source":"https://ubuntu.com/security/cve?package=linux-oem-6.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.0","debian":"https://tracker.debian.org/pkg/linux-oem-6.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-oem-6.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oem-6.1","component":null,"pocket":"security"}]},{"name":"linux-oem-6.1","source":"https://ubuntu.com/security/cve?package=linux-oem-6.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.1","debian":"https://tracker.debian.org/pkg/linux-oem-6.1","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-oem-6.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oem-6.5","component":null,"pocket":"security"}]},{"name":"linux-oem-6.5","source":"https://ubuntu.com/security/cve?package=linux-oem-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.5","debian":"https://tracker.debian.org/pkg/linux-oem-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-oem-6.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oem-6.8","component":null,"pocket":"security"}]},{"name":"linux-oem-6.8","source":"https://ubuntu.com/security/cve?package=linux-oem-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.8","debian":"https://tracker.debian.org/pkg/linux-oem-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-oem-6.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oem-6.14","component":null,"pocket":"security"}]},{"name":"linux-oem-6.11","source":"https://ubuntu.com/security/cve?package=linux-oem-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.11","debian":"https://tracker.debian.org/pkg/linux-oem-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-oem-6.14","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-oem-6.14","component":null,"pocket":"security"}]},{"name":"linux-oem-6.14","source":"https://ubuntu.com/security/cve?package=linux-oem-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.14","debian":"https://tracker.debian.org/pkg/linux-oem-6.14","statuses":[{"release_codename":"noble","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.17","source":"https://ubuntu.com/security/cve?package=linux-oem-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.17","debian":"https://tracker.debian.org/pkg/linux-oem-6.17","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"7.0.0-1004.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"replaced by linux-raspi","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi-realtime","source":"https://ubuntu.com/security/cve?package=linux-raspi-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-realtime","debian":"https://tracker.debian.org/pkg/linux-raspi-realtime","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-realtime","source":"https://ubuntu.com/security/cve?package=linux-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime","debian":"https://tracker.debian.org/pkg/linux-realtime","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"realtime"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"realtime"},{"release_codename":"resolute","status":"not-affected","description":"7.0.0-10.10.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.8","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.8","debian":"https://tracker.debian.org/pkg/linux-realtime-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.14","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.14","debian":"https://tracker.debian.org/pkg/linux-realtime-6.14","statuses":[{"release_codename":"noble","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"7.0.0-7.7.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"replaced by linux-riscv-6.14","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.8","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.8","debian":"https://tracker.debian.org/pkg/linux-riscv-5.8","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-riscv-5.11","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.11","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.11","debian":"https://tracker.debian.org/pkg/linux-riscv-5.11","statuses":[{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-riscv-5.13","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.15","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.15","debian":"https://tracker.debian.org/pkg/linux-riscv-5.15","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.19","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.19","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.19","debian":"https://tracker.debian.org/pkg/linux-riscv-5.19","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.5","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.5","debian":"https://tracker.debian.org/pkg/linux-riscv-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-riscv-6.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-riscv-6.8","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.8","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.8","debian":"https://tracker.debian.org/pkg/linux-riscv-6.8","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.14","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.14","debian":"https://tracker.debian.org/pkg/linux-riscv-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-riscv-6.17","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-riscv-6.17","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.17","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.17","debian":"https://tracker.debian.org/pkg/linux-riscv-6.17","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-starfive-5.19","source":"https://ubuntu.com/security/cve?package=linux-starfive-5.19","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-starfive-5.19","debian":"https://tracker.debian.org/pkg/linux-starfive-5.19","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-starfive-6.2","source":"https://ubuntu.com/security/cve?package=linux-starfive-6.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-starfive-6.2","debian":"https://tracker.debian.org/pkg/linux-starfive-6.2","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"superseded by linux-starfive-6.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"superseded by linux-starfive-6.5","component":null,"pocket":"security"}]},{"name":"linux-starfive-6.5","source":"https://ubuntu.com/security/cve?package=linux-starfive-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-starfive-6.5","debian":"https://tracker.debian.org/pkg/linux-starfive-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"linux-xilinx","source":"https://ubuntu.com/security/cve?package=linux-xilinx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-xilinx","debian":"https://tracker.debian.org/pkg/linux-xilinx","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-xilinx-zynqmp","source":"https://ubuntu.com/security/cve?package=linux-xilinx-zynqmp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-xilinx-zynqmp","debian":"https://tracker.debian.org/pkg/linux-xilinx-zynqmp","statuses":[{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.17","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.17","debian":"https://tracker.debian.org/pkg/linux-realtime-6.17","statuses":[{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"end of life, was needed","component":null,"pocket":"realtime"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-7.0","source":"https://ubuntu.com/security/cve?package=linux-hwe-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-7.0","debian":"https://tracker.debian.org/pkg/linux-hwe-7.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"7.0.0-14.14~24.04.3","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]},{"name":"linux-oem-7.0","source":"https://ubuntu.com/security/cve?package=linux-oem-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-7.0","debian":"https://tracker.debian.org/pkg/linux-oem-7.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"7.0.0-1005.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]},{"name":"linux-nvidia-7.0","source":"https://ubuntu.com/security/cve?package=linux-nvidia-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-7.0","debian":"https://tracker.debian.org/pkg/linux-nvidia-7.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"7.0.0-1013.13~24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]},{"name":"linux-nvidia-bos","source":"https://ubuntu.com/security/cve?package=linux-nvidia-bos","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-bos","debian":"https://tracker.debian.org/pkg/linux-nvidia-bos","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"7.0.0-2015.15","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]},{"name":"linux-aws-7.0","source":"https://ubuntu.com/security/cve?package=linux-aws-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-7.0","debian":"https://tracker.debian.org/pkg/linux-aws-7.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"7.0.0-1009.9~24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]},{"name":"linux-riscv-7.0","source":"https://ubuntu.com/security/cve?package=linux-riscv-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-7.0","debian":"https://tracker.debian.org/pkg/linux-riscv-7.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"7.0.0-27.27.1~24.04.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]},{"name":"linux-azure-7.0","source":"https://ubuntu.com/security/cve?package=linux-azure-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-7.0","debian":"https://tracker.debian.org/pkg/linux-azure-7.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"7.0.0-1008.8~24.04.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-7.0","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-7.0","debian":"https://tracker.debian.org/pkg/linux-azure-fde-7.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]},{"name":"linux-gcp-7.0","source":"https://ubuntu.com/security/cve?package=linux-gcp-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-7.0","debian":"https://tracker.debian.org/pkg/linux-gcp-7.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"7.0.0-1006.6~24.04.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]},{"name":"linux-oracle-7.0","source":"https://ubuntu.com/security/cve?package=linux-oracle-7.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-7.0","debian":"https://tracker.debian.org/pkg/linux-oracle-7.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"7.0.0-1006.6~24.04.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.19~rc1, 6.8.y, 6.17.y","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-37248","published":"2026-06-08T16:16:00","updated_at":"2026-06-18T18:33:26.427134+00:00","description":"\nOfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability\nprior to authentication, which allows STRIPTLS/man-in-the-middle attacks,\ntaking over the connection and extracting account credentials in cleartext.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2020-37248","https://github.com/OfflineIMAP/offlineimap3/issues/222","https://github.com/OfflineIMAP/offlineimap/issues/669","https://github.com/OfflineIMAP/offlineimap3/commit/46505c53ef995455d66c685f9ec3ff6ea93dbb74","https://pypi.org/project/offlineimap/#history","http://www.openwall.com/lists/oss-security/2026/06/08/3"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139329"],"patches":{"offlineimap3":[]},"tags":{},"packages":[{"name":"offlineimap3","source":"https://ubuntu.com/security/cve?package=offlineimap3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=offlineimap3","debian":"https://tracker.debian.org/pkg/offlineimap3","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9549","published":"2026-06-08T13:16:00","updated_at":"2026-06-18T18:50:57.591090+00:00","description":"\nStored cross-site scripting in the service discovery active check output in\nCheckmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an\nadministrator who can configure active or custom checks to inject malicious\nHTML or JavaScript into check output that executes in the browser of an\nadmin or a user with host read permissions when they run the check on the\nservice discovery page.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9549","https://checkmk.com/werk/17993"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-8833","published":"2026-06-08T13:16:00","updated_at":"2026-06-18T18:16:51.538779+00:00","description":"\nImproper neutralization of HTML-encoded characters in the URL validation\nfunction in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions\nallows an authenticated user to bypass URL validation and inject malicious\nURLs such as javascript: URIs, resulting in cross-site scripting when\nanother user interacts with the crafted link.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8833","https://checkmk.com/werk/20002"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-8078","published":"2026-06-08T13:16:00","updated_at":"2026-06-18T18:50:46.033692+00:00","description":"\nStored cross-site scripting in the global settings change log in Checkmk\n<2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an\nadministrator who can change global settings to store malicious HTML or\nJavaScript in changelog messages that executes in other users' browsers\nwhen they view the Activate Changes page or Audit log.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8078","https://checkmk.com/werk/17992"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7765","published":"2026-06-08T13:16:00","updated_at":"2026-06-18T18:16:51.538779+00:00","description":"\nIncorrect authorization in the User Messages dashboard widget in Checkmk\n<2.5.0p5 causes the message-fetching endpoints to return the dashboard\ncreator's messages rather than the viewer's, allowing an attacker who knows\na valid public dashboard share token to read the issuer's personal messages\nby sending requests to the underlying endpoint, even without a User\nMessages widget present.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7765","https://checkmk.com/werk/19815"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-7186","published":"2026-06-08T13:16:00","updated_at":"2026-06-18T18:50:34.770567+00:00","description":"\nStored cross-site scripting in the URL dashboard widget in Checkmk\n<2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with\ndashboard editing permissions to store a URL with a dangerous URI scheme\nsuch as javascript: that executes scripts in other users' browsers when\nthey view the dashboard.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-7186","https://checkmk.com/werk/17991"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47895","published":"2026-06-08T12:00:00","updated_at":"2026-09-02T21:05:21.480688+00:00","description":"\nIn strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed\nEAP-Identities that result in an empty but non-NULL encoding are not\ncorrectly cloned and trigger a double-free once the duplicates are\ndestroyed.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47895","https://github.com/strongswan/strongswan/releases/tag/6.0.7","https://www.strongswan.org/blog/2026/06/08/strongswan-vulnerability-(cve-2026-47895).html","https://ubuntu.com/security/notices/USN-8407-1"],"bugs":[""],"patches":{"strongswan":[]},"tags":{},"packages":[{"name":"strongswan","source":"https://ubuntu.com/security/cve?package=strongswan","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=strongswan","debian":"https://tracker.debian.org/pkg/strongswan","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"5.9.5-2ubuntu2.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"5.9.13-2ubuntu4.24.04.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"6.0.1-6ubuntu4.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"6.0.4-1ubuntu3.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8407-1"],"notices":[{"id":"USN-8407-1","title":"strongSwan vulnerability","summary":"strongSwan could be made to crash or run programs if it received specially\ncrafted network traffic.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-08T17:28:38.144440","description":"Elliott Childre discovered that strongSwan incorrectly handled the cloning\nof certain identities. A remote attacker could use this issue to cause\nstrongSwan to crash, resulting in a denial of service, or possibly execute\narbitrary code.","is_hidden":false,"release_packages":{"jammy":[{"name":"strongswan","version":"5.9.5-2ubuntu2.7","description":"IPsec VPN solution","is_source":true},{"name":"charon-cmd","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"charon-systemd","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"libcharon-extauth-plugins","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"libcharon-extra-plugins","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"libstrongswan","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"libstrongswan-extra-plugins","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"libstrongswan-standard-plugins","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"strongswan","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"strongswan-charon","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"strongswan-libcharon","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"strongswan-nm","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"strongswan-pki","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"strongswan-scepclient","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"strongswan-starter","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"},{"name":"strongswan-swanctl","version":"5.9.5-2ubuntu2.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.5-2ubuntu2.7","pocket":"security"}],"noble":[{"name":"strongswan","version":"5.9.13-2ubuntu4.24.04.4","description":"IPsec VPN solution","is_source":true},{"name":"charon-cmd","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"charon-systemd","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"libcharon-extauth-plugins","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"libcharon-extra-plugins","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"libstrongswan","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"libstrongswan-extra-plugins","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"libstrongswan-standard-plugins","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"strongswan","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"strongswan-charon","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"strongswan-libcharon","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"strongswan-nm","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"strongswan-pki","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"strongswan-starter","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"},{"name":"strongswan-swanctl","version":"5.9.13-2ubuntu4.24.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/5.9.13-2ubuntu4.24.04.4","pocket":"security"}],"questing":[{"name":"strongswan","version":"6.0.1-6ubuntu4.4","description":"IPsec VPN solution","is_source":true},{"name":"charon-cmd","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"charon-systemd","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"libcharon-extauth-plugins","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"libcharon-extra-plugins","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"libstrongswan","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"libstrongswan-extra-plugins","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"libstrongswan-standard-plugins","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"strongswan","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"strongswan-charon","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"strongswan-libcharon","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"strongswan-nm","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"strongswan-pki","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"strongswan-starter","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"},{"name":"strongswan-swanctl","version":"6.0.1-6ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.1-6ubuntu4.4","pocket":"security"}],"resolute":[{"name":"strongswan","version":"6.0.4-1ubuntu3.1","description":"IPsec VPN solution","is_source":true},{"name":"charon-cmd","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"charon-systemd","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"libcharon-extauth-plugins","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"libcharon-extra-plugins","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"libstrongswan","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"libstrongswan-extra-plugins","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"libstrongswan-standard-plugins","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"strongswan","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"strongswan-charon","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"strongswan-libcharon","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"strongswan-nm","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"strongswan-pki","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"strongswan-starter","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"},{"name":"strongswan-swanctl","version":"6.0.4-1ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/strongswan","version_link":"https://launchpad.net/ubuntu/+source/strongswan/6.0.4-1ubuntu3.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-47895"]}]},{"id":"CVE-2026-48977","published":"2026-06-08T00:00:00","updated_at":"2026-06-08T12:41:11.100734+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48977","https://github.com/openslide/openslide/security/advisories/GHSA-mxg2-48g7-fmwc"],"bugs":[""],"patches":{"openslide":[]},"tags":{},"packages":[{"name":"openslide","source":"https://ubuntu.com/security/cve?package=openslide","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openslide","debian":"https://tracker.debian.org/pkg/openslide","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-47321","published":"2026-06-08T00:00:00","updated_at":"2026-06-08T12:41:11.100734+00:00","description":"\n[Unknown description]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47321","https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139162"],"patches":{"mina":[],"mina2":[]},"tags":{},"packages":[{"name":"mina","source":"https://ubuntu.com/security/cve?package=mina","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mina","debian":"https://tracker.debian.org/pkg/mina","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mina2","source":"https://ubuntu.com/security/cve?package=mina2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mina2","debian":"https://tracker.debian.org/pkg/mina2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11487","published":"2026-06-08T00:00:00","updated_at":"2026-06-18T18:42:03.219606+00:00","description":"\nA flaw has been found in Neovim up to 0.12.2. Affected by this issue is the\nfunction M.read of the file runtime/lua/vim/secure.lua of the component\nView Branch. Executing a manipulation of the argument path can lead to\ncommand injection. It is possible to launch the attack on the local host.\nThe exploit has been published and may be used. This patch is called\nf83e0dcaf8cf18de94828341b0a1a61a86c75baf. A patch should be applied to\nremediate this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11487","https://github.com/neovim/neovim/issues/39914","https://github.com/neovim/neovim/pull/39918","https://github.com/neovim/neovim/commit/f83e0dcaf8cf18de94828341b0a1a61a86c75baf"],"bugs":[""],"patches":{"neovim":[]},"tags":{},"packages":[{"name":"neovim","source":"https://ubuntu.com/security/cve?package=neovim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=neovim","debian":"https://tracker.debian.org/pkg/neovim","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":10060,"limit":20,"total_results":79316}