{"cves":[{"id":"CVE-2026-1402","published":"2026-05-27T19:16:00","updated_at":"2026-06-06T11:40:43.307665+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that\nunder certain conditions could have allowed an authenticated user to cause\ndenial of service due to insufficient validation.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1402","https://about.gitlab.com/releases/2026/05/27/patch-release-gitlab-19-0-1-released/","https://gitlab.com/gitlab-org/gitlab/-/work_items/587569","https://hackerone.com/reports/3517283"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44378","published":"2026-05-27T18:16:00","updated_at":"2026-06-06T01:47:08.350114+00:00","description":"\nBotan is a C++ cryptography library. Prior to 3.12.0, certain patterns of\nindefinite length encodings in BER data could cause quadratic behavior in\nthe parser, resulting in a denial of service. Such BER encodings were\naccepted even in structures which are required to be encoded as DER, which\nprohibits indefinite length encodings. This vulnerability is fixed in\n3.12.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44378","https://github.com/randombit/botan/security/advisories/GHSA-7q2v-3g27-6g3j"],"bugs":[""],"patches":{"botan3":[]},"tags":{},"packages":[{"name":"botan3","source":"https://ubuntu.com/security/cve?package=botan3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=botan3","debian":"https://tracker.debian.org/pkg/botan3","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44353","published":"2026-05-27T17:16:00","updated_at":"2026-06-06T01:47:08.350114+00:00","description":"\nStreamlink is a CLI utility which pipes video streams from various services\ninto a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do\nnot validate the URI scheme of segment entries and other resources. A\nremote .m3u8 HLS playlist or .mpd DASH manifest can list\nfile:///path/to/file as a segment, and streamlink will read that local file\nand write its contents to the output stream. This vulnerability is fixed in\n8.4.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44353","https://github.com/streamlink/streamlink/security/advisories/GHSA-hgqw-6m45-hw5f"],"bugs":[""],"patches":{"streamlink":[]},"tags":{},"packages":[{"name":"streamlink","source":"https://ubuntu.com/security/cve?package=streamlink","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=streamlink","debian":"https://tracker.debian.org/pkg/streamlink","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.4.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42790","published":"2026-05-27T17:16:00","updated_at":"2026-08-07T14:01:42.016111+00:00","description":"\nImproper Certificate Validation vulnerability in Erlang OTP public_key\n(pubkey_cert and public_key modules) allows a DNS nameConstraints bypass\nvia subject CommonName fallback in TLS hostname verification.\nTwo flaws combine to allow a subordinate CA whose DNS nameConstraints are\nrestricted (e.g. permitted;DNS:allowed.example.com) to issue a leaf\ncertificate that an OTP TLS client accepts as a valid identity for an\nout-of-scope hostname (e.g. victim.example.com):\nFirst, pubkey_cert:validate_names/6 in lib/public_key/src/pubkey_cert.erl\nonly checks SAN DNS entries against nameConstraints. Per RFC 5280, a\npermitted DNS subtree only restricts certificates that contain a DNS-typed\nname. A leaf with no subjectAltName therefore trivially satisfies any\npermitted;DNS:... constraint regardless of its subject commonName.\nSecond, public_key:pkix_verify_hostname/3 in\nlib/public_key/src/public_key.erl falls back to the subject commonName when\nno subjectAltName is present, extracting id-at-commonName attributes as\npresented IDs and matching them against the reference hostname. The strict\npkix_verify_hostname_match_fun(https) matcher does not suppress this\nfallback.\nThe result is that path validation accepts a CN-only leaf under a\nDNS-constrained intermediate (no SAN means the nameConstraints are not\ntriggered), and hostname verification then accepts it via the CN fallback.\nThe bypass is reachable from stock ssl:connect with verify_peer, a trusted\nCA, SNI, and the canonical strict https hostname matcher.\nThis issue affects OTP from OTP 19.3 before OTP 29.0.1, OTP 28.5.0.1,\nOTP 27.3.4.12 and OTP 26.2.5.21, corresponding to public_key from 1.4\nbefore 1.21.1, 1.20.3.1, 1.17.1.3 and 1.15.1.7.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42790","https://github.com/erlang/otp/security/advisories/GHSA-22cw-4ph4-6447","https://cna.erlef.org/cves/CVE-2026-42790.html","https://osv.dev/vulnerability/EEF-CVE-2026-42790","https://github.com/erlang/otp/commit/0769050c69d73762672b0db1347b6993a5b31759 (OTP-26.2.5.21)","https://github.com/erlang/otp/commit/fb67c6d1836f51105a96d8b769e71e4215a79457 (OTP-27.3.4.12)","https://github.com/erlang/otp/commit/21abed64eb2026b5f82f432709e4e932f9be389a (OTP-29.0.1, OTP-28.5.0.1)","https://github.com/erlang/otp/commit/0769050c69d73762672b0db1347b6993a5b31759","https://github.com/erlang/otp/commit/21abed64eb2026b5f82f432709e4e932f9be389a","https://github.com/erlang/otp/commit/fb67c6d1836f51105a96d8b769e71e4215a79457","https://www.erlang.org/doc/system/versions.html#order-of-versions"],"bugs":[""],"patches":{"erlang":[]},"tags":{},"packages":[{"name":"erlang","source":"https://ubuntu.com/security/cve?package=erlang","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=erlang","debian":"https://tracker.debian.org/pkg/erlang","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:27.3.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-70116","published":"2026-05-27T17:16:00","updated_at":"2026-06-06T05:13:11.405275+00:00","description":"\nA NULL pointer dereference in GPAC MP4Box: when parsing certain truncated\nMP4 files, an unknown/invalid stsd entry can result in missing descriptor\nfields (e.g., codec/mime/profile strings). gf_media_map_esd then calls\nstrlen() on a NULL pointer, triggering a crash (ASan SEGV).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-70116","https://github.com/gpac/gpac/issues/3345"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45571","published":"2026-05-27T15:16:00","updated_at":"2026-06-06T01:47:32.192077+00:00","description":"\ngo-git is an extensible git implementation library written in pure Go.\nPrior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could\nallow crafted repository data to affect files outside the intended checkout\ntarget, including the repository's .git directory. These validations were\nintroduced in upstream Git years ago, so the vulnerability arose from\ngo-git drifting from those checks. This vulnerability is fixed in 5.19.1\nand 6.0.0-alpha.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45571","https://github.com/go-git/go-git/security/advisories/GHSA-crhj-59gh-8x96"],"bugs":[""],"patches":{"golang-github-go-git-go-git":[]},"tags":{},"packages":[{"name":"golang-github-go-git-go-git","source":"https://ubuntu.com/security/cve?package=golang-github-go-git-go-git","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-go-git-go-git","debian":"https://tracker.debian.org/pkg/golang-github-go-git-go-git","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.19.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45570","published":"2026-05-27T15:16:00","updated_at":"2026-06-08T05:21:24.235937+00:00","description":"\ngo-git is an extensible git implementation library written in pure Go.\nPrior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the\nremote exec command by wrapping the repository path in single quotes\nwithout escaping single quotes embedded inside the path. A repository path\ncontaining a single quote can therefore break out of the quoted region in\nthe exec command and be appended as additional shell tokens. This\nvulnerability is fixed in 5.19.1 and 6.0.0-alpha.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"}},"baseScore":2.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45570","https://github.com/go-git/go-git/security/advisories/GHSA-m7cr-m3pv-hgrp"],"bugs":[""],"patches":{"golang-github-go-git-go-git":[]},"tags":{},"packages":[{"name":"golang-github-go-git-go-git","source":"https://ubuntu.com/security/cve?package=golang-github-go-git-go-git","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-go-git-go-git","debian":"https://tracker.debian.org/pkg/golang-github-go-git-go-git","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.19.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45022","published":"2026-05-27T15:16:00","updated_at":"2026-06-08T05:21:24.235937+00:00","description":"\ngo-git is an extensible git implementation library written in pure Go.\nPrior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects\nin a way that differs from upstream Git. When commit or tag objects contain\nambiguous or malformed headers, go-git’s decoded representation may expose\nvalues differently from how Git itself would interpret or reject the same\nobject. Additionally, go-git’s commit signing and verification logic\noperates over commit data reconstructed from go-git’s parsed representation\nrather than the original raw object bytes. As a result, go-git may sign or\nverify a commit payload that is not byte-for-byte equivalent to the object\nstored in the repository. This can cause a signature to appear valid for a\ncommit whose displayed or effective metadata differs from the object that\nwas intended to be signed. This vulnerability is fixed in 5.19.0 and\n6.0.0-alpha.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45022","https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp"],"bugs":[""],"patches":{"golang-github-go-git-go-git":[]},"tags":{},"packages":[{"name":"golang-github-go-git-go-git","source":"https://ubuntu.com/security/cve?package=golang-github-go-git-go-git","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-go-git-go-git","debian":"https://tracker.debian.org/pkg/golang-github-go-git-go-git","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.19.1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44988","published":"2026-05-27T15:16:00","updated_at":"2026-06-26T06:34:56.287437+00:00","description":"\nLibVNCClient is a library for easy implementation of a VNC client. In\n0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size\n2048-pixel scratch buffers for the Gradient filter, but it does not reject\nTight rectangles whose width is larger than 2048 pixels. A malicious VNC\nserver can send a crafted FramebufferUpdate rectangle using Tight encoding\nwith NoZlib | ExplicitFilter and the Gradient filter. When a\nLibVNCClient-based client connects, the client processes the\nserver-controlled rectangle width and writes beyond fixed-size Gradient\nbuffers. This vulnerability is fixed with commit\n5b270544b85233668b98161323297d418a8f5fd1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44988","https://github.com/LibVNC/libvncserver/security/advisories/GHSA-jcc5-8wj4-7c58","https://ubuntu.com/security/notices/USN-8463-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138174"],"patches":{"libvncserver":["upstream: https://github.com/LibVNC/libvncserver/commit/5b270544b85233668b98161323297d418a8f5fd1"],"vino":[],"x11vnc":[],"veyon":[],"italc":[],"tightvnc":[]},"tags":{},"packages":[{"name":"libvncserver","source":"https://ubuntu.com/security/cve?package=libvncserver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libvncserver","debian":"https://tracker.debian.org/pkg/libvncserver","statuses":[{"release_codename":"upstream","status":"released","description":"0.9.15+dfsg-5","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.9.14+dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"0.9.15+dfsg-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.9.15+dfsg-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.9.13+dfsg-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"vino","source":"https://ubuntu.com/security/cve?package=vino","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vino","debian":"https://tracker.debian.org/pkg/vino","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"x11vnc","source":"https://ubuntu.com/security/cve?package=x11vnc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=x11vnc","debian":"https://tracker.debian.org/pkg/x11vnc","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"veyon","source":"https://ubuntu.com/security/cve?package=veyon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=veyon","debian":"https://tracker.debian.org/pkg/veyon","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"italc","source":"https://ubuntu.com/security/cve?package=italc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=italc","debian":"https://tracker.debian.org/pkg/italc","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"tightvnc","source":"https://ubuntu.com/security/cve?package=tightvnc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tightvnc","debian":"https://tracker.debian.org/pkg/tightvnc","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8463-1"],"notices":[{"id":"USN-8463-1","title":"LibVNCServer vulnerabilities","summary":"Several security issues were fixed in LibVNCServer.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-23T14:46:54.375752","description":"It was discovered that LibVNCServer had a memory leak in the client cleanup\nfunction. An attacker could possibly use this issue to cause LibVNCServer\nto consume memory, leading to a denial of service. This issue only affected\nUbuntu 22.04 LTS. (CVE-2020-29260)\n\nIt was discovered that LibVNCServer did not properly validate bounds when\nhandling UltraZip encoding subrectangles. A remote attacker could possibly\nuse this issue to obtain sensitive information or cause a denial of\nservice. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 25.04. (CVE-2026-32853)\n\nIt was discovered that LibVNCServer did not properly validate return values\nin the HTTP proxy handlers. A remote attacker could possibly use this issue\nto cause LibVNCServer to crash, resulting in a denial of service. This\nissue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 25.04.\n(CVE-2026-32854)\n\nIt was discovered that LibVNCServer did not properly handle Tight encoding\ngradient filter rectangles. A remote attacker could use this issue to cause\nLibVNCServer to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-44988)","is_hidden":false,"release_packages":{"jammy":[{"name":"libvncserver","version":"0.9.13+dfsg-3ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.13+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.13+dfsg-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.13+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.13+dfsg-3ubuntu0.1","pocket":"security"}],"noble":[{"name":"libvncserver","version":"0.9.14+dfsg-1ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.14+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.14+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.14+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.14+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.14+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.14+dfsg-1ubuntu0.1","pocket":"security"}],"questing":[{"name":"libvncserver","version":"0.9.15+dfsg-1ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.15+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.15+dfsg-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-1ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.15+dfsg-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-1ubuntu0.1","pocket":"security"}],"resolute":[{"name":"libvncserver","version":"0.9.15+dfsg-3ubuntu0.1","description":"vnc server library","is_source":true},{"name":"libvncclient1","version":"0.9.15+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver-dev","version":"0.9.15+dfsg-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-3ubuntu0.1","pocket":"security"},{"name":"libvncserver1","version":"0.9.15+dfsg-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libvncserver","version_link":"https://launchpad.net/ubuntu/+source/libvncserver/0.9.15+dfsg-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-29260","CVE-2026-32853","CVE-2026-44988","CVE-2026-32854"]}]},{"id":"CVE-2026-44839","published":"2026-05-27T15:16:00","updated_at":"2026-06-08T05:21:24.235937+00:00","description":"\nRabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2\nand 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44839","https://github.com/rabbitmq/rabbitmq-server/commit/7f54319279d1ece161ae0b4cdc6f0e58a4045eb5","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-fh5r-jpm3-fjwp"],"bugs":[""],"patches":{"broker":[]},"tags":{},"packages":[{"name":"broker","source":"https://ubuntu.com/security/cve?package=broker","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=broker","debian":"https://tracker.debian.org/pkg/broker","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44838","published":"2026-05-27T15:16:00","updated_at":"2026-06-08T05:21:24.235937+00:00","description":"\nRabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4,\nRabbitMQ's MQTT plugin allows for topic-level authorization using regular\nexpressions with variable substitution. Administrators can create patterns\nsuch as ^{client_id}-sensors$ to restrict user access to topics that\ninclude their client ID. However, the client_id is provided by the user in\nthe MQTT CONNECT packet and is inserted into the regex pattern without\nescaping special regex characters. This flaw enables an authenticated MQTT\nuser to inject regex operators to bypass authorization. This vulnerability\nis fixed in 4.2.4 and 4.3.0.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Per upstream rabbitmq-server developers, this only affects\n4.2.0+"}],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:H/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44838","https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-x866-xp2g-cx8v"],"bugs":[""],"patches":{"rabbitmq-server":["upstream: https://github.com/rabbitmq/rabbitmq-server/commit/df0fb8eb1023067e33aab343d9412e05b7849044"]},"tags":{},"packages":[{"name":"rabbitmq-server","source":"https://ubuntu.com/security/cve?package=rabbitmq-server","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rabbitmq-server","debian":"https://tracker.debian.org/pkg/rabbitmq-server","statuses":[{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-37713","published":"2026-05-27T15:16:00","updated_at":"2026-06-06T05:13:11.405275+00:00","description":"\nAn issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha\nallows a remote attacker to execute arbitrary code via the\nhtdocs/core/class/commonobject.class.php.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-37713"],"bugs":[""],"patches":{"dolibarr":[]},"tags":{},"packages":[{"name":"dolibarr","source":"https://ubuntu.com/security/cve?package=dolibarr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dolibarr","debian":"https://tracker.debian.org/pkg/dolibarr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-37712","published":"2026-05-27T15:16:00","updated_at":"2026-06-06T05:13:11.405275+00:00","description":"\nAn issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha\nallows a remote attacker to execute arbitrary code via the\nhtdocs/cron/class/cronjob.class.php, call_user_func_array() in function job\ntype","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-37712"],"bugs":[""],"patches":{"dolibarr":[]},"tags":{},"packages":[{"name":"dolibarr","source":"https://ubuntu.com/security/cve?package=dolibarr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dolibarr","debian":"https://tracker.debian.org/pkg/dolibarr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-37711","published":"2026-05-27T15:16:00","updated_at":"2026-06-06T05:13:11.405275+00:00","description":"\nAn issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha\nallows a remote attacker to execute arbitrary code via the\nhtdocs/core/actions_addupdatedelete.inc.php","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-37711"],"bugs":[""],"patches":{"dolibarr":[]},"tags":{},"packages":[{"name":"dolibarr","source":"https://ubuntu.com/security/cve?package=dolibarr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=dolibarr","debian":"https://tracker.debian.org/pkg/dolibarr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-70103","published":"2026-05-27T15:16:00","updated_at":"2026-06-08T18:32:08.068788+00:00","description":"\nHeap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images\nto the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-70103","https://github.com/libjxl/libjxl/pull/4338","https://github.com/sigdevel/pocs/blob/main/res/libjxl/2025/2","https://infosec.exchange/@sigdevel/116642233929409910","https://ubuntu.com/security/notices/USN-8397-1"],"bugs":["https://github.com/libjxl/libjxl/issues/4337"],"patches":{"jpeg-xl":["upstream: https://github.com/libjxl/libjxl/commit/49fb89f23473e57fa1dac416adce7c7679e5d051"]},"tags":{},"packages":[{"name":"jpeg-xl","source":"https://ubuntu.com/security/cve?package=jpeg-xl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jpeg-xl","debian":"https://tracker.debian.org/pkg/jpeg-xl","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"0.11.1-6ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.11.1-6ubuntu4.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-8397-1"],"notices":[{"id":"USN-8397-1","title":"libjxl vulnerability","summary":"libjxl could be made to crash or run programs if it opened a specially\ncrafted file.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-08T12:20:37.253802","description":"It was discovered that libjxl did not properly handle certain crafted PBM\nimages. An attacker could possibly use this issue to cause libjxl to crash,\nresulting in a denial of service, or execute arbitrary code.","is_hidden":false,"release_packages":{"questing":[{"name":"jpeg-xl","version":"0.11.1-6ubuntu1.2","description":"Reference codec implementation for JPEG XL compressed raster image format","is_source":true},{"name":"jpeg-xl-doc","version":"0.11.1-6ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu1.2","pocket":"security"},{"name":"libjpegxl-java","version":"0.11.1-6ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu1.2","pocket":"security"},{"name":"libjxl-dev","version":"0.11.1-6ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu1.2","pocket":"security"},{"name":"libjxl-devtools","version":"0.11.1-6ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu1.2","pocket":"security"},{"name":"libjxl-gdk-pixbuf","version":"0.11.1-6ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu1.2","pocket":"security"},{"name":"libjxl-tools","version":"0.11.1-6ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu1.2","pocket":"security"},{"name":"libjxl0.11","version":"0.11.1-6ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu1.2","pocket":"security"}],"resolute":[{"name":"jpeg-xl","version":"0.11.1-6ubuntu4.2","description":"Reference codec implementation for JPEG XL compressed raster image format","is_source":true},{"name":"jpeg-xl-doc","version":"0.11.1-6ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu4.2","pocket":"security"},{"name":"libjpegxl-java","version":"0.11.1-6ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu4.2","pocket":"security"},{"name":"libjxl-dev","version":"0.11.1-6ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu4.2","pocket":"security"},{"name":"libjxl-devtools","version":"0.11.1-6ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu4.2","pocket":"security"},{"name":"libjxl-gdk-pixbuf","version":"0.11.1-6ubuntu4.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu4.2","pocket":"security"},{"name":"libjxl-tools","version":"0.11.1-6ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu4.2","pocket":"security"},{"name":"libjxl0.11","version":"0.11.1-6ubuntu4.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jpeg-xl","version_link":"https://launchpad.net/ubuntu/+source/jpeg-xl/0.11.1-6ubuntu4.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-70103"]}]},{"id":"CVE-2026-47104","published":"2026-05-27T14:17:00","updated_at":"2026-06-06T01:51:21.650614+00:00","description":"\nlibusb before version 1.0.30 contains a one-byte out-of-bounds read\nvulnerability in parse_iad_array() in descriptor.c that allows attackers to\ntrigger a denial of service by supplying a malformed USB descriptor whose\nbLength equals size minus one, causing the bounds check to use the original\nbuffer size instead of the remaining size. Attackers in virtualized\nenvironments with USB passthrough can supply crafted descriptors through\nlibusb_get_active_interface_association_descriptors or\nlibusb_get_interface_association_descriptors to read one byte past the end\nof the malloc allocation, resulting in a denial of service.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same commits as CVE-2026-23679"}],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.0,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47104","https://github.com/libusb/libusb/commit/578ab76b4c434f8b204137ab6d7310689c7a9704","https://github.com/libusb/libusb/pull/1814","https://github.com/libusb/libusb/releases/tag/v1.0.30","https://www.vulncheck.com/advisories/libusb-out-of-bounds-read-in-parse-iad-array"],"bugs":["https://github.com/libusb/libusb/issues/1813"],"patches":{"libusb":["upstream: https://github.com/libusb/libusb/commit/016a0de33ac94b19c7772d6c20fbea7fec23bf68","upstream: https://github.com/libusb/libusb/commit/bc0886173ea15b8cc9bba2918f58a97a7f185231"]},"tags":{},"packages":[{"name":"libusb","source":"https://ubuntu.com/security/cve?package=libusb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libusb","debian":"https://tracker.debian.org/pkg/libusb","statuses":[{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42791","published":"2026-05-27T14:16:00","updated_at":"2026-08-07T14:01:42.016111+00:00","description":"\nImproper Certificate Validation vulnerability in Erlang OTP public_key\n(pubkey_ocsp module) allows forged OCSP responses signed with an expired\nresponder certificate to be accepted as valid.\nOCSP response verification in pubkey_ocsp:verify_response/5 and\npubkey_ocsp:is_authorized_responder/3 in lib/public_key/src/pubkey_ocsp.erl\ndoes not check the validity period (notBefore/notAfter) of the OCSP\nresponder certificate. An attacker who has obtained the private key of an\nexpired CA-designated OCSP responder certificate can forge OCSP responses\nthat Erlang/OTP accepts as valid.\nThis affects TLS clients using OCSP stapling via the ssl application: a\nmalicious or compromised server can present a revoked TLS certificate\ntogether with a forged OCSP response signed by an expired responder key,\nand the client will accept the revoked certificate as valid. It also\naffects applications calling public_key:pkix_ocsp_validate/5 directly,\nwhere the impact depends on the use case — server-side client certificate\nvalidation using this API may allow authentication bypass with a revoked\nclient certificate.\nThis issue affects OTP from OTP 27.0 before OTP 29.0.1, OTP 28.5.0.1 and\nOTP 27.3.4.12, corresponding to public_key from 1.16 before 1.21.1,\n1.20.3.1 and 1.17.1.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42791","https://github.com/erlang/otp/security/advisories/GHSA-cjxj-wj6x-3fff","https://cna.erlef.org/cves/CVE-2026-42791.html","https://osv.dev/vulnerability/EEF-CVE-2026-42791","https://github.com/erlang/otp/commit/7995f1fdaee3da569bb810358ce0f546471d169b (OTP-27.3.4.12)","https://github.com/erlang/otp/commit/b3870e02405c709a872b01ba6086065620cdfe76 (OTP-29.0.1, OTP-28.5.0.1)","https://github.com/erlang/otp/commit/7995f1fdaee3da569bb810358ce0f546471d169b","https://github.com/erlang/otp/commit/b3870e02405c709a872b01ba6086065620cdfe76","https://www.erlang.org/doc/system/versions.html#order-of-versions"],"bugs":[""],"patches":{"erlang":[]},"tags":{},"packages":[{"name":"erlang","source":"https://ubuntu.com/security/cve?package=erlang","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=erlang","debian":"https://tracker.debian.org/pkg/erlang","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:27.3.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42789","published":"2026-05-27T14:16:00","updated_at":"2026-08-07T14:01:42.016111+00:00","description":"\nImproper Following of a Certificate's Chain of Trust vulnerability in\nErlang OTP public_key (pubkey_cert module) allows a non-CA certificate to\nbe accepted as an intermediate issuer, enabling certificate chain forgery.\nIn lib/public_key/src/pubkey_cert.erl, pubkey_cert:validate_extensions/7\ncontains two flaws that together allow a certificate with basicConstraints\ncA:false and no keyUsage extension to be used as an intermediate issuer in\na chain passed to public_key:pkix_path_validation/3: the cA:false clause\nrecurses into the remaining extensions without rejecting the certificate\nwhen it is in issuer position, and the keyUsage check only fires when the\nextension is present, so a certificate lacking keyUsage entirely bypasses\nthe keyCertSign enforcement.\nAny party holding an end-entity certificate with basicConstraints cA:false\nand no keyUsage extension, issued by any CA in the victim's trust store,\ncan use that certificate's private key to sign forged leaf certificates for\narbitrary identities. public_key:pkix_path_validation/3 accepts the\nresulting chain, and by extension every TLS or mTLS endpoint built on the\nOTP ssl application that relies on the default verifier is affected,\nincluding server identity verification on the client side and client\ncertificate verification on mTLS servers.\nThis issue affects OTP from OTP 17.0 before OTP 29.0.1, OTP 28.5.0.1,\nOTP 27.3.4.12 and OTP 26.2.5.21, corresponding to public_key from 0.22\nbefore 1.21.1, 1.20.3.1, 1.17.1.3 and 1.15.1.7.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.0,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42789","https://github.com/erlang/otp/security/advisories/GHSA-c99q-jmpx-v8qq","https://cna.erlef.org/cves/CVE-2026-42789.html","https://osv.dev/vulnerability/EEF-CVE-2026-42789","https://github.com/erlang/otp/commit/471cd2f664300a95353c467873800bbe706005db (OTP-26.2.5.21)","https://github.com/erlang/otp/commit/59c8d824386b2eb1614ff9340624843ef6aca0fd (OTP-29.0.1, OTP-28.5.0.1, OTP-27.3.4.12)","https://github.com/erlang/otp/commit/471cd2f664300a95353c467873800bbe706005db","https://github.com/erlang/otp/commit/59c8d824386b2eb1614ff9340624843ef6aca0fd","https://www.erlang.org/doc/system/versions.html#order-of-versions"],"bugs":[""],"patches":{"erlang":[]},"tags":{},"packages":[{"name":"erlang","source":"https://ubuntu.com/security/cve?package=erlang","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=erlang","debian":"https://tracker.debian.org/pkg/erlang","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:27.3.4.12+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-23679","published":"2026-05-27T14:16:00","updated_at":"2026-06-06T01:46:48.022605+00:00","description":"\nlibusb before version 1.0.30 contains a NULL pointer dereference\nvulnerability that allows attackers to crash applications by supplying a\nmalformed USB configuration descriptor where an interface claims\nbNumEndpoints greater than zero but is followed by a class-specific\ndescriptor whose bLength exceeds the remaining buffer size, causing\nparse_interface() to return early without allocating the endpoint array.\nAttackers can exploit this flaw through libusb_get_active_config_descriptor\nor libusb_get_config_descriptor by providing crafted descriptors via\nvirtualized USB passthrough, file-based descriptor parsing, or network\nsources, causing any application iterating over endpoints to dereference a\nNULL endpoint pointer and crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23679","https://github.com/libusb/libusb/commit/578ab76b4c434f8b204137ab6d7310689c7a9704","https://github.com/libusb/libusb/pull/1814","https://github.com/libusb/libusb/releases/tag/v1.0.30","https://www.vulncheck.com/advisories/libusb-null-pointer-dereference-in-parse-interface"],"bugs":["https://github.com/libusb/libusb/issues/1813"],"patches":{"libusb":["upstream: https://github.com/libusb/libusb/commit/016a0de33ac94b19c7772d6c20fbea7fec23bf68","upstream: https://github.com/libusb/libusb/commit/bc0886173ea15b8cc9bba2918f58a97a7f185231"]},"tags":{},"packages":[{"name":"libusb","source":"https://ubuntu.com/security/cve?package=libusb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libusb","debian":"https://tracker.debian.org/pkg/libusb","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-8450","published":"2026-05-27T05:16:00","updated_at":"2026-06-10T18:34:43.139068+00:00","description":"\nHTTP::Daemon versions before 6.17 for Perl allow OS command injection via\nsend_file().\nsend_file() opens its string argument with Perl's 2-arg open(). The 2-arg\nform interprets magic prefixes: '| cmd' and 'cmd |' open a pipe to a\nsubprocess, '> path' and '>> path' open the path for write or append.\nUntrusted input passed to send_file() can run OS commands at the daemon\nprocess UID. The read-pipe form ('cmd |') also leaks subprocess stdout into\nthe HTTP response body. The write-mode forms can create or truncate files\nat attacker chosen paths.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8450","https://lists.security.metacpan.org/cve-announce/msg/40435207/","https://github.com/libwww-perl/HTTP-Daemon/pull/89","https://metacpan.org/release/OALDERS/HTTP-Daemon-6.17/changes","http://www.openwall.com/lists/oss-security/2026/05/27/5","https://ubuntu.com/security/notices/USN-8419-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138050"],"patches":{"libhttp-daemon-perl":["upstream: https://github.com/libwww-perl/HTTP-Daemon/commit/945d35141d94490f749640bd4390acd6a2193995"]},"tags":{},"packages":[{"name":"libhttp-daemon-perl","source":"https://ubuntu.com/security/cve?package=libhttp-daemon-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libhttp-daemon-perl","debian":"https://tracker.debian.org/pkg/libhttp-daemon-perl","statuses":[{"release_codename":"upstream","status":"released","description":"6.17-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"6.01-1ubuntu0.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"6.06-1ubuntu0.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"6.13-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"6.16-1ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"6.16-1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"6.16-1ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"6.01-1ubuntu0.14.04~esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"6.01-1ubuntu0.16.04~esm2","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8419-1"],"notices":[{"id":"USN-8419-1","title":"HTTP-Daemon vulnerability","summary":"HTTP-Daemon could be made to run programs if it received specially crafted\nnetwork traffic.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-10T13:49:41.366191","description":"It was discovered that HTTP-Daemon incorrectly handled untrusted input\nunder certain circumstances. A remote attacker could possibly use this\nissue to execute arbitrary commands, create or overwrite arbitrary files,\nor expose sensitive information.","is_hidden":false,"release_packages":{"bionic":[{"name":"libhttp-daemon-perl","version":"6.01-1ubuntu0.1+esm1","description":"simple http server class","is_source":true},{"name":"libhttp-daemon-perl","version":"6.01-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"libhttp-daemon-perl","version":"6.06-1ubuntu0.1+esm1","description":"simple http server class","is_source":true},{"name":"libhttp-daemon-perl","version":"6.06-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"libhttp-daemon-perl","version":"6.13-1ubuntu0.2","description":"simple http server class","is_source":true},{"name":"libhttp-daemon-perl","version":"6.13-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl","version_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl/6.13-1ubuntu0.2","pocket":"security"}],"noble":[{"name":"libhttp-daemon-perl","version":"6.16-1ubuntu0.24.04.1","description":"simple http server class","is_source":true},{"name":"libhttp-daemon-perl","version":"6.16-1ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl","version_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl/6.16-1ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"libhttp-daemon-perl","version":"6.16-1ubuntu0.25.10.1","description":"simple http server class","is_source":true},{"name":"libhttp-daemon-perl","version":"6.16-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl","version_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl/6.16-1ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"libhttp-daemon-perl","version":"6.16-1ubuntu0.26.04.1","description":"simple http server class","is_source":true},{"name":"libhttp-daemon-perl","version":"6.16-1ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl","version_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl/6.16-1ubuntu0.26.04.1","pocket":"security"}],"trusty":[{"name":"libhttp-daemon-perl","version":"6.01-1ubuntu0.14.04~esm2","description":"simple http server class","is_source":true},{"name":"libhttp-daemon-perl","version":"6.01-1ubuntu0.14.04~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libhttp-daemon-perl","version":"6.01-1ubuntu0.16.04~esm2","description":"simple http server class","is_source":true},{"name":"libhttp-daemon-perl","version":"6.01-1ubuntu0.16.04~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libhttp-daemon-perl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-8450"]}]}],"offset":10920,"limit":20,"total_results":79316}