{"cves":[{"id":"CVE-2026-11099","published":"2026-06-08T00:00:00","updated_at":"2026-06-08T12:34:04.124073+00:00","description":"\nsecurity update","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11099"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11053","published":"2026-06-08T00:00:00","updated_at":"2026-06-08T12:32:19.652799+00:00","description":"\nsecurity update","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11053"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-10725","published":"2026-06-06T10:16:00","updated_at":"2026-06-18T18:33:48.186255+00:00","description":"\nProtocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2\nBomb.\nProtocol::HTTP2's inbound HPACK path has no header-list size limit, so a\nsmall HTTP/2 request can expand into large server memory (the \"HTTP/2\nbomb\").\nThe headers_decode method materialises a full key+value copy per indexed\nreference with no running size check, and the stream_header_block_add\nmethod appends (since version 1.12) every CONTINUATION frame to the\nper-stream buffer unbounded.\nMAX_HEADER_LIST_SIZE (default 65536) is advertised in SETTINGS but never\nconsulted on decode. It is absent from the decoder and from the :limits\nexport tag.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-10725","https://lists.security.metacpan.org/cve-announce/msg/40751319/","https://security.metacpan.org/patches/P/Protocol-HTTP2/1.12/CVE-2026-10725-r1.patch","https://metacpan.org/release/CRUX/Protocol-HTTP2-1.12/source/lib/Protocol/HTTP2/HeaderCompression.pm#L133","https://metacpan.org/release/CRUX/Protocol-HTTP2-1.12/source/lib/Protocol/HTTP2/Stream.pm#L414","http://www.openwall.com/lists/oss-security/2026/06/06/7"],"bugs":[""],"patches":{"libprotocol-http2-perl":[]},"tags":{},"packages":[{"name":"libprotocol-http2-perl","source":"https://ubuntu.com/security/cve?package=libprotocol-http2-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libprotocol-http2-perl","debian":"https://tracker.debian.org/pkg/libprotocol-http2-perl","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45409","published":"2026-06-05T23:16:00","updated_at":"2026-09-11T03:39:44.065995+00:00","description":"\nInternationalized Domain Names in Applications (IDNA) for Python provides\nsupport for Internationalized Domain Names in Applications (IDNA) and\nUnicode IDNA Compatibility Processing. In versions prior to 3.15, payloads\nsuch as `\"\\u0660\" * N` or `\"\\u30fb\" * N + \"\\u6f22\"` utilize the\n`valid_contexto` function prior to length rejection, and for high values of\n`N` will take a long time to process. This is the same issue as\nCVE-2024-3651, however the original remediation in 2024 was not a complete\nfix. A specially crafted argument to the `idna.encode()` function could\nconsume significant resources. This may lead to a denial-of-service.\nStarting in version 3.14, the function rejects long inputs as soon as\npracticable prior to any further processing to minimize resource\nconsumption. In version 3.15, this approach was extended to lesser used\nalternate functions (i.e. per-label conversions and codec support). A\nworkaround is available. Domain names cannot exceed 253 characters in\nlength. If this length limit is enforced prior to passing the domain to the\n`idna.encode()` function, it should no longer consume significant\nresources. This is triggered by arbitrarily large inputs that would not\noccur in normal usage, but may be passed to the library assuming there is\nno preliminary input validation by the higher-level application.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"On focal and earlier, the python-pip package bundles\npython-idna binaries when built. After updating\npython-idna, a no-change rebuild of python-pip is required.\nOn jammy and later, python-idna is bundled in the python-pip\npackage and needs to be patched."}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45409","https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx","https://ubuntu.com/security/notices/USN-8549-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139164"],"patches":{"python-idna":["upstream: https://github.com/kjd/idna/commit/c0dda4501df5d91c3181ce6f962dc5de74e82cc1","upstream: https://github.com/kjd/idna/commit/628fef84d3eda59321c21127e73dcd873db23ead","upstream: https://github.com/kjd/idna/commit/e1cb465b6376f33306a26f467d197edbcd01c4b9"],"python-pip":["upstream: https://github.com/kjd/idna/commit/c0dda4501df5d91c3181ce6f962dc5de74e82cc1","upstream: https://github.com/kjd/idna/commit/628fef84d3eda59321c21127e73dcd873db23ead","upstream: https://github.com/kjd/idna/commit/e1cb465b6376f33306a26f467d197edbcd01c4b9"]},"tags":{},"packages":[{"name":"python-idna","source":"https://ubuntu.com/security/cve?package=python-idna","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-idna","debian":"https://tracker.debian.org/pkg/python-idna","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.6-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.11-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.11-1.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.3-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python-pip","source":"https://ubuntu.com/security/cve?package=python-pip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-pip","debian":"https://tracker.debian.org/pkg/python-pip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8549-1"],"notices":[{"id":"USN-8549-1","title":"idna vulnerability","summary":"idna could be made to consume resources if it received specially crafted\ninput.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-15T13:46:50.191175","description":"It was discovered that idna did not properly reject oversized inputs before\nperforming expensive processing. An attacker could possibly use this issue\nto cause idna to consume significant resources, leading to a denial of\nservice.","is_hidden":false,"release_packages":{"jammy":[{"name":"python-idna","version":"3.3-1ubuntu0.2","description":"Python IDNA2008 (RFC 5891) handling","is_source":true},{"name":"python3-idna","version":"3.3-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-idna","version_link":"https://launchpad.net/ubuntu/+source/python-idna/3.3-1ubuntu0.2","pocket":"security"}],"noble":[{"name":"python-idna","version":"3.6-2ubuntu0.2","description":"Python IDNA2008 (RFC 5891) handling","is_source":true},{"name":"python3-idna","version":"3.6-2ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-idna","version_link":"https://launchpad.net/ubuntu/+source/python-idna/3.6-2ubuntu0.2","pocket":"security"}],"resolute":[{"name":"python-idna","version":"3.11-1ubuntu0.1","description":"Python IDNA2008 (RFC 5891) handling","is_source":true},{"name":"python3-idna","version":"3.11-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-idna","version_link":"https://launchpad.net/ubuntu/+source/python-idna/3.11-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-45409"]}]},{"id":"CVE-2026-45300","published":"2026-06-05T20:17:00","updated_at":"2026-06-18T18:45:29.489991+00:00","description":"\nThe AsyncHttpClient (AHC) library allows Java applications to easily\nexecute HTTP requests and asynchronously process HTTP responses. Versions\non the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak\n`Cookie` headers to cross-origin redirect targets. When following a\nredirect to a different origin, the `propagatedHeaders()` method in\n`Redirect30xInterceptor.java` strips `Authorization` and\n`Proxy-Authorization` headers but does not strip the `Cookie` header,\ncausing session cookies and other sensitive cookie values to be sent to\nattacker-controlled servers. Versions 2.15.0 and 3.0.10 patch the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45300","https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-fmxf-pm6p-7xgm","https://github.com/AsyncHttpClient/async-http-client/commit/3b0e3e9e","https://github.com/AsyncHttpClient/async-http-client/releases/tag/async-http-client-project-3.0.10"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139165"],"patches":{"async-http-client":[]},"tags":{},"packages":[{"name":"async-http-client","source":"https://ubuntu.com/security/cve?package=async-http-client","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=async-http-client","debian":"https://tracker.debian.org/pkg/async-http-client","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48112","published":"2026-06-05T17:16:00","updated_at":"2026-06-18T18:49:32.176598+00:00","description":"\n7-Zip is a file archiver with a high compression ratio. Versions 9.18\nthrough 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD\nSYMDEF parser. A 4-byte heap out-of-bounds read exists in the Unix ar\narchive parser in 7-Zip. When parsing a BSD-style __.SYMDEF symbol table,\nthe ParseLibSymbols function reads a 32-bit namesSize field via Get32 at a\nposition that can equal the buffer size, reading 4 bytes past the end of\nthe heap allocation. This reads uninitialized heap data under the default\nallocator. Version 26.01 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48112","https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/"],"bugs":[""],"patches":{"7zip":[],"p7zip":[]},"tags":{},"packages":[{"name":"7zip","source":"https://ubuntu.com/security/cve?package=7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=7zip","debian":"https://tracker.debian.org/pkg/7zip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.01+dfsg-1","component":null,"pocket":"security"}]},{"name":"p7zip","source":"https://ubuntu.com/security/cve?package=p7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=p7zip","debian":"https://tracker.debian.org/pkg/p7zip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"16.02+transitional.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.02+transitional.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48111","published":"2026-06-05T17:16:00","updated_at":"2026-06-18T18:49:32.176598+00:00","description":"\n7-Zip is a file archiver with a high compression ratio. Versions 9.21\nthrough 26.00 contain an off-by-one out-of-bounds read vulnerability in the\nParseDepedencyExpression function of the UEFI firmware image\nparser(CPP/7zip/Archive/UefiHandler.cpp). The function validates an\nattacker-controlled opcode byte using > instead of >= against the element\ncount of the 10-entry kExpressionCommands static array, allowing an opcode\nvalue of 10 to read one pointer slot (8 bytes on x64) past the end of the\narray in .rodata. The out-of-bounds value is then dereferenced as a const\nchar * and passed through strlen and memcpy into the archive's Characts\nproperty, which may cause either a denial of service (access violation when\nthe adjacent bytes do not form a valid readable pointer) or a minor\ninformation disclosure of an adjacent .rdata string literal into archive\nmetadata. The vulnerability is reached automatically during\nIInArchive::Open() via the call path OpenFv/OpenCapsule → ParseVolume →\nParseSections when processing a SECTION_DXE_DEPEX (0x13) or\nSECTION_PEI_DEPEX (0x1B) section whose first body byte is 0x0A, and the\nUEFI handler is enabled by default in stock 7z.dll with signature-based\ndetection for both UEFIc and UEFIf formats. The outcome (crash vs. silent\nleak) is deterministic per build but linker-layout dependent, with no write\nprimitive and no disclosure of heap data, secrets, or ASLR base addresses.\nVersion 26.01 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48111","https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/"],"bugs":[""],"patches":{"7zip":[],"p7zip":[]},"tags":{},"packages":[{"name":"7zip","source":"https://ubuntu.com/security/cve?package=7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=7zip","debian":"https://tracker.debian.org/pkg/7zip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.01+dfsg-1","component":null,"pocket":"security"}]},{"name":"p7zip","source":"https://ubuntu.com/security/cve?package=p7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=p7zip","debian":"https://tracker.debian.org/pkg/p7zip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"16.02+transitional.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.02+transitional.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48104","published":"2026-06-05T17:16:00","updated_at":"2026-06-18T18:49:32.176598+00:00","description":"\n7-Zip is a file archiver with a high compression ratio. Versions 9.18\nthrough 26.00 contain an uninitialized heap read in the SquashFS archive\nhandler caused by a sparsely populated index array. In the SquashFS\nhandler, _blockToNode is allocated with capacity for every metadata block\nbut populated only when an inode crosses a block boundary, so a crafted\nimage with few inodes spanning many blocks leaves most slots holding raw\nheap contents (the underlying allocator does not zero-initialize POD\nstorage). When OpenDir looks up an attacker-influenced blockIndex (derived\nfrom the RootInode superblock field), it reads two of these uninitialized\nslots and passes them as the left/right bounds of a binary search over\n_nodesPos, which dereferences the midpoint without bounds checking; if the\nresulting value happens to match the search key, the returned index is used\nto read a full node struct from _nodes whose fields feed further directory\nparsing, forming a chained OOB read primitive that is heap-layout-dependent\nand not reliably triggerable. The SquashFS handler is enabled by default in\nstock 7z.dll and the issue triggers during Open() with no interaction\nbeyond opening the file; impact is denial of service from wild-pointer\ndereference and potential heap information disclosure, with no write\nprimitive. Version 26.01 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48104","https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/"],"bugs":[""],"patches":{"7zip":[],"p7zip":[]},"tags":{},"packages":[{"name":"7zip","source":"https://ubuntu.com/security/cve?package=7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=7zip","debian":"https://tracker.debian.org/pkg/7zip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.01+dfsg-1","component":null,"pocket":"security"}]},{"name":"p7zip","source":"https://ubuntu.com/security/cve?package=p7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=p7zip","debian":"https://tracker.debian.org/pkg/p7zip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"16.02+transitional.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.02+transitional.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48103","published":"2026-06-05T17:16:00","updated_at":"2026-06-18T18:49:32.176598+00:00","description":"\n7-Zip is a file archiver with a high compression ratio. Versions 9.34\nthrough 26.00 contain an off-by-one heap out-of-bounds read in the WIM\n(Windows Imaging) archive handler's security descriptor lookup. In\nCHandler::GetSecurity (CPP/7zip/Archive/Wim/WimHandler.cpp), the per-image\nSecurOffsets table holds numEntries + 1 cumulative offsets, but the check\nsecurityId >= SecurOffsets.Size() admits securityId == numEntries, and the\nfunction then reads SecurOffsets[securityId + 1], fetching one UInt32 past\nthe end of the heap-allocated CRecordVector (which performs no bounds\nchecking on operator[]). The securityId is attacker-controlled at offset\n+0xC of any directory entry in WIM metadata, and the handler is registered\nfor .wim, .swm, .esd, and .ppkg and enabled by default in stock 7z.dll; the\nOOB triggers zero-click in the GUI because 7zFM.exe's ListView calls\nGetRawProp(kpidNtSecure) for every item during listing (ASan-confirmed),\nand is also reachable via CLI listing with 7zz l -slt. Impact is limited to\ndenial of service under hardened allocators and minor information\ndisclosure, since the OOB value is only consumed arithmetically as a length\nand is not surfaced to the attacker; there is no write primitive.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48103","https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/"],"bugs":[""],"patches":{"7zip":[],"p7zip":[]},"tags":{},"packages":[{"name":"7zip","source":"https://ubuntu.com/security/cve?package=7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=7zip","debian":"https://tracker.debian.org/pkg/7zip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.01+dfsg-1","component":null,"pocket":"security"}]},{"name":"p7zip","source":"https://ubuntu.com/security/cve?package=p7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=p7zip","debian":"https://tracker.debian.org/pkg/p7zip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"16.02+transitional.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.02+transitional.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48102","published":"2026-06-05T16:16:00","updated_at":"2026-06-18T18:49:32.176598+00:00","description":"\n7-Zip is a file archiver with a high compression ratio. Versions 9.11\nthrough 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF\ndisc image handler's File Identifier Descriptor parser. In CFileId::Parse\n(CPP/7zip/Archive/Udf/UdfIn.cpp), after validating size < 38 + idLen +\nimpLen and advancing processed to 38 + impLen + idLen, the\nalignment-padding loop reads p[processed] while incrementing up to 3 times\nto reach a 4-byte boundary, and the processed <= size bounds check only\nruns after the loop. When (38 + impLen + idLen) % 4 != 0 and 38 + impLen +\nidLen == size, the loop reads 1 to 3 bytes past the end of the exact-size\nheap buffer allocated via buf.Alloc((size_t)item.Size). The UDF handler is\nregistered for .iso and .udf files and auto-detected by signature, and the\nOOB read triggers during Open() when listing or extracting a crafted UDF\nimage. Impact is limited to information disclosure (a 1-bit oracle per OOB\nbyte via open/fail behavior) and denial of service (crash under hardened\nallocators); there is no write primitive. Version 26.01 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48102","https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/"],"bugs":[""],"patches":{"7zip":[],"p7zip":[]},"tags":{},"packages":[{"name":"7zip","source":"https://ubuntu.com/security/cve?package=7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=7zip","debian":"https://tracker.debian.org/pkg/7zip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.01+dfsg-1","component":null,"pocket":"security"}]},{"name":"p7zip","source":"https://ubuntu.com/security/cve?package=p7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=p7zip","debian":"https://tracker.debian.org/pkg/p7zip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"16.02+transitional.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.02+transitional.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48101","published":"2026-06-05T16:16:00","updated_at":"2026-06-18T18:49:32.176598+00:00","description":"\n7-Zip is a file archiver with a high compression ratio. Versions 9.21\nthrough 26.00 contain an An uninitialized memory disclosure vulnerability\nin the UEFI capsule (.scap) parser in 7-Zip. The OpenCapsule function\nallocates a heap buffer of attacker-declared CapsuleImageSize (up to 1 GiB)\nwithout zero-initialization, then reads the file contents into it with\nReadStream_FALSE whose return value is silently discarded. If the file is\ntruncated, the unread tail of the buffer retains uninitialized heap memory,\nwhich is then exposed as extracted file content via GetStream. Version\n26.0.1 fixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48101","https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/"],"bugs":[""],"patches":{"7zip":[],"p7zip":[]},"tags":{},"packages":[{"name":"7zip","source":"https://ubuntu.com/security/cve?package=7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=7zip","debian":"https://tracker.debian.org/pkg/7zip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.01+dfsg-1","component":null,"pocket":"security"}]},{"name":"p7zip","source":"https://ubuntu.com/security/cve?package=p7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=p7zip","debian":"https://tracker.debian.org/pkg/p7zip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"16.02+transitional.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.02+transitional.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48095","published":"2026-06-05T15:16:00","updated_at":"2026-06-18T18:49:32.176598+00:00","description":"\n7-Zip is a file archiver with a high compression ratio. Versions 26.00 and\nprior contain a heap buffer overflow vulnerability caused by an\nunder-allocation in the NTFS compressed stream buffer (GetCuSize shift UB),\npotentially allowing attackers to cause arbitrary code execution or\napplication crashes. CInStream::GetCuSize() in the NTFS handler computes\nthe compression-unit buffer size as (UInt32)1 << (BlockSizeLog +\nCompressionUnit), and a crafted image with ClusterSizeLog >= 28 and\nCompressionUnit == 4 drives the exponent to 32, which is undefined behavior\nand collapses on x86/x64 so _inBuf is allocated as 1 byte. ReadStream_FALSE\nthen writes up to 256 MB of attacker-controlled data into that 1-byte\nbuffer in 64 KB iterations, and because the CInStream object sits only 304\nbytes after _inBuf, its vtable pointer is overwritten and the next\ndispatched call achieves a vtable hijack. On 32-bit builds the overflow is\nunconditionally reached; on 64-bit it requires the parallel 8 GB _outBuf\nallocation to succeed, otherwise failing closed to denial of service. The\nNTFS handler is enabled by default in stock 7z.dll and, via signature-based\nfallback matching \"NTFS \" at offset 3, will open a crafted image\nregardless of file extension during extraction or testing. Version 26.01\nfixes the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48095","https://securitylab.github.com/advisories/GHSL-2026-140_7-Zip/"],"bugs":[""],"patches":{"7zip":[],"p7zip":[]},"tags":{},"packages":[{"name":"7zip","source":"https://ubuntu.com/security/cve?package=7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=7zip","debian":"https://tracker.debian.org/pkg/7zip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.01+dfsg-1","component":null,"pocket":"security"}]},{"name":"p7zip","source":"https://ubuntu.com/security/cve?package=p7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=p7zip","debian":"https://tracker.debian.org/pkg/p7zip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"16.02+transitional.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.02+transitional.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48092","published":"2026-06-05T15:16:00","updated_at":"2026-06-18T18:49:32.176598+00:00","description":"\n7-Zip is a file archiver with a high compression ratio. Versions 9.34\nthrough 26.00 contain a heap memory disclosure via SquashFS fragment offset\ninteger overflow on 32-bit builds. 32-bit integer overflow in the SquashFS\nReadBlock function allows an attacker-controlled node.Offset value to\nbypass the fragment bounds check, causing memcpy to read heap memory\npreceding the cache buffer into the extracted file. The vulnerability is\nexploitable only on 32-bit builds of 7-Zip where size_t is 32 bits,\nallowing the addition offsetInBlock + blockSize to wrap modulo 2³². On\n64-bit builds the addition is promoted to 64 bits and the check correctly\nrejects the input. Version 26.01 patches the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48092","https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/"],"bugs":[""],"patches":{"7zip":[],"p7zip":[]},"tags":{},"packages":[{"name":"7zip","source":"https://ubuntu.com/security/cve?package=7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=7zip","debian":"https://tracker.debian.org/pkg/7zip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"26.01+dfsg-1","component":null,"pocket":"security"}]},{"name":"p7zip","source":"https://ubuntu.com/security/cve?package=p7zip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=p7zip","debian":"https://tracker.debian.org/pkg/p7zip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"16.02+transitional.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"16.02+transitional.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-10879","published":"2026-06-05T15:16:00","updated_at":"2026-06-25T15:39:18.399948+00:00","description":"\nDBI versions before 1.648 for Perl have a heap overflow when preparsing SQL\nstatements with more than 9 binders.\nThe preparse method expands SQL placeholder characters to numbered binders\nof the form :pN, but only allocates three characters per binder in the\nbuffer. Placeholders 10-99 require four characters, 100-999 require five\ncharacters, et cetera.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-10879","https://lists.security.metacpan.org/cve-announce/msg/40729086/","https://github.com/perl5-dbi/dbi/commit/af79036c07aa9a457971c0f4136e37c85dc20978.patch","https://metacpan.org/release/HMBRAND/DBI-1.648/changes","http://www.openwall.com/lists/oss-security/2026/06/06/4","https://ubuntu.com/security/notices/USN-8466-1"],"bugs":[""],"patches":{"libdbi-perl":[]},"tags":{},"packages":[{"name":"libdbi-perl","source":"https://ubuntu.com/security/cve?package=libdbi-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libdbi-perl","debian":"https://tracker.debian.org/pkg/libdbi-perl","statuses":[{"release_codename":"bionic","status":"released","description":"1.640-1ubuntu0.3+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.643-1ubuntu0.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"1.643-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.643-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.647-1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.647-1ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.630-1ubuntu0.1~esm6","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.634-1ubuntu0.2+esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"upstream","status":"released","description":"1.648-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8466-1"],"notices":[{"id":"USN-8466-1","title":"Perl DBI module vulnerabilities","summary":"Several security issues were fixed in Perl DBI module.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-24T09:30:53.352952","description":"It was discovered that the Perl DBI module incorrectly handled certain\nerror messages. An attacker could use this issue to cause applications\nusing the Perl DBI module to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-9698)\n\nIt was discovered that the Perl DBI module incorrectly handled memory when\npreparsing SQL statements that included more than nine binders. An attacker\ncould use this issue to cause applications using the Perl DBI module to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2026-10879)","is_hidden":false,"release_packages":{"bionic":[{"name":"libdbi-perl","version":"1.640-1ubuntu0.3+esm1","description":"Perl Database Interface (DBI)","is_source":true},{"name":"libdbi-perl","version":"1.640-1ubuntu0.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libdbi-perl","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"libdbi-perl","version":"1.643-1ubuntu0.1+esm1","description":"Perl Database Interface (DBI)","is_source":true},{"name":"libdbi-perl","version":"1.643-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libdbi-perl","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libdbi-perl","version":"1.643-3ubuntu0.1","description":"Perl Database Interface (DBI)","is_source":true},{"name":"libdbi-perl","version":"1.643-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libdbi-perl","version_link":"https://launchpad.net/ubuntu/+source/libdbi-perl/1.643-3ubuntu0.1","pocket":"security"}],"noble":[{"name":"libdbi-perl","version":"1.643-4ubuntu0.1","description":"Perl Database Interface (DBI)","is_source":true},{"name":"libdbi-perl","version":"1.643-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libdbi-perl","version_link":"https://launchpad.net/ubuntu/+source/libdbi-perl/1.643-4ubuntu0.1","pocket":"security"}],"questing":[{"name":"libdbi-perl","version":"1.647-1ubuntu0.25.10.1","description":"Perl Database Interface (DBI)","is_source":true},{"name":"libdbi-perl","version":"1.647-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libdbi-perl","version_link":"https://launchpad.net/ubuntu/+source/libdbi-perl/1.647-1ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"libdbi-perl","version":"1.647-1ubuntu0.26.04.1","description":"Perl Database Interface (DBI)","is_source":true},{"name":"libdbi-perl","version":"1.647-1ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libdbi-perl","version_link":"https://launchpad.net/ubuntu/+source/libdbi-perl/1.647-1ubuntu0.26.04.1","pocket":"security"}],"trusty":[{"name":"libdbi-perl","version":"1.630-1ubuntu0.1~esm6","description":"Perl Database Interface (DBI)","is_source":true},{"name":"libdbi-perl","version":"1.630-1ubuntu0.1~esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libdbi-perl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libdbi-perl","version":"1.634-1ubuntu0.2+esm2","description":"Perl Database Interface (DBI)","is_source":true},{"name":"libdbi-perl","version":"1.634-1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libdbi-perl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-10879","CVE-2026-9698"]}]},{"id":"CVE-2026-11329","published":"2026-06-05T13:16:00","updated_at":"2026-06-18T18:42:03.219606+00:00","description":"\nA vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by\nthis issue is the function generate_hash_key of the file\nsrc/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of the\ncomponent Placeholder Node Cache Handler. Such manipulation leads to use of\nweak hash. An attack has to be approached locally. A high complexity level\nis associated with this attack. The exploitation is known to be difficult.\nThe name of the patch is 72c5187ff6d13c2c2b3d3789b8f5faf99f08a5b4. Applying\na patch is advised to resolve this issue.","ubuntu_description":"","notes":[{"author":"federicoquattrin","note":"This CVE affects onnx-mlir. ONNX is not affected."}],"codename":null,"priority":"medium","cvss3":3.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":3.6,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.0,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11329","https://github.com/onnx/onnx-mlir/","https://github.com/onnx/onnx-mlir/commit/72c5187ff6d13c2c2b3d3789b8f5faf99f08a5b4","https://github.com/onnx/onnx-mlir/pull/3427","https://vuldb.com/cve/CVE-2026-11329","https://vuldb.com/submit/832358","https://vuldb.com/vuln/368865","https://vuldb.com/vuln/368865/cti"],"bugs":[""],"patches":{"onnx":[]},"tags":{},"packages":[{"name":"onnx","source":"https://ubuntu.com/security/cve?package=onnx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=onnx","debian":"https://tracker.debian.org/pkg/onnx","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50265","published":"2026-06-05T11:16:00","updated_at":"2026-06-18T19:22:38.468639+00:00","description":"\nRejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50265","https://access.redhat.com/security/cve/CVE-2026-50265","https://bugzilla.redhat.com/show_bug.cgi?id=2485390","https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1296","http://www.openwall.com/lists/oss-security/2026/06/04/16"],"bugs":[""],"patches":{"libinput":[]},"tags":{},"packages":[{"name":"libinput","source":"https://ubuntu.com/security/cve?package=libinput","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libinput","debian":"https://tracker.debian.org/pkg/libinput","statuses":[{"release_codename":"bionic","status":"not-affected","description":"REJECTED CVE","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"REJECTED CVE","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"REJECTED CVE","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"REJECTED CVE","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"REJECTED CVE","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"REJECTED CVE","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"REJECTED CVE","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11332","published":"2026-06-05T09:16:00","updated_at":"2026-06-18T18:42:03.219606+00:00","description":"\nA flaw was found in ansible-core. The ansible-galaxy role install command\nprocesses dependency specifications from a role's meta/requirements.yml\nfile. Due to improper neutralization of argument delimiters, a malicious\nrole author can inject arbitrary git configuration flags through the src\nfield. This allows arbitrary code execution on the machine of a user who\ninstalls the role via ansible-galaxy role install.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"core ansible binaries were split into ansible-base, which\ngot renamed to ansible-core\ncore ansible binaries were split into ansible-base, which\ngot renamed to ansible-core"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11332","https://bugzilla.redhat.com/show_bug.cgi?id=2485379","https://github.com/ansible/ansible/pull/87070","https://access.redhat.com/security/cve/CVE-2026-11332","https://github.com/ansible/ansible"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139175"],"patches":{"ansible":[],"ansible-core":[]},"tags":{},"packages":[{"name":"ansible","source":"https://ubuntu.com/security/cve?package=ansible","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ansible","debian":"https://tracker.debian.org/pkg/ansible","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ansible-core","source":"https://ubuntu.com/security/cve?package=ansible-core","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ansible-core","debian":"https://tracker.debian.org/pkg/ansible-core","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41567","published":"2026-06-05T02:17:00","updated_at":"2026-06-18T18:44:22.717829+00:00","description":"\nMoby is an open source container framework. In versions prior to 29.5.1 and\nin moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is\nuploaded to a container via `PUT /containers/{id}/archive` or piped through\n`docker cp -`, the daemon resolves decompression binaries (such as `xz` or\n`unpigz`) from the container's filesystem rather than the host's due to\nincorrect ordering of operations. A malicious container image containing a\ntrojanized decompression binary can achieve arbitrary code execution with\nfull daemon privileges, including host root UID and unrestricted\ncapabilities, when a user uploads a compressed (xz or gzip) archive into\nthat container. This issue is fixed in Docker Engine 29.5.1 and moby/moby\nv2.0.0-beta.14. Workarounds include only running containers from trusted\nimages, using authorization plugins to restrict access to the `PUT\n/containers/{id}/archive` endpoint, and avoiding piping compressed archives\ninto containers created from untrusted images","ubuntu_description":"","notes":[{"author":"alexmurray","note":"Traditionally the docker.io source package contained both the\nlibrary and docker application. However, in releases that\ncontain the\ndocker.io-app source package, the docker.io source package\ncontains only\nthe library whilst the docker application itself is contained\nin the\ndocker.io-app package."},{"author":"sbeattie","note":"docker packages contain an embedded copy of github:moby/buildkit"},{"author":"alexmurray","note":"Traditionally the docker.io source package contained both the\nlibrary and docker application. However, in releases that\ncontain the\ndocker.io-app source package, the docker.io source package\ncontains only\nthe library whilst the docker application itself is contained\nin the\ndocker.io-app package."},{"author":"sbeattie","note":"docker packages contain an embedded copy of github:moby/buildkit"}],"codename":null,"priority":"medium","cvss3":7.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41567"],"bugs":[""],"patches":{"docker.io":[],"docker.io-app":[]},"tags":{},"packages":[{"name":"docker.io","source":"https://ubuntu.com/security/cve?package=docker.io","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=docker.io","debian":"https://tracker.debian.org/pkg/docker.io","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"docker.io-app","source":"https://ubuntu.com/security/cve?package=docker.io-app","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=docker.io-app","debian":"https://tracker.debian.org/pkg/docker.io-app","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50589","published":"2026-06-05T00:17:00","updated_at":"2026-06-18T18:50:18.015983+00:00","description":"\nIn OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user\ncould submit a crafted JSON string to some endpoints on the API or JSON-RPC\nservice and effect a service crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50589","https://bugs.launchpad.net/ironic/+bug/2154288","https://wiki.openstack.org/wiki/OSSN/OSSN-0099","http://www.openwall.com/lists/oss-security/2026/06/06/2"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138908"],"patches":{"ironic":[]},"tags":{},"packages":[{"name":"ironic","source":"https://ubuntu.com/security/cve?package=ironic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ironic","debian":"https://tracker.debian.org/pkg/ironic","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:35.0.1-5","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11309","published":"2026-06-05T00:17:00","updated_at":"2026-06-18T18:42:03.219606+00:00","description":"\nInsufficient policy enforcement in History in Google Chrome prior to\n149.0.7827.53 allowed a remote attacker to perform UI spoofing via a\ncrafted HTML page. (Chromium security severity: Low)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11309","https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/506392934"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":10080,"limit":20,"total_results":79316}