{"cves":[{"id":"CVE-2026-42506","published":"2026-05-22T16:16:00","updated_at":"2026-05-27T19:16:31.452854+00:00","description":"\nParsing arbitrary HTML which is then rendered using Render can result in an\nunexpected HTML tree. This can be leveraged to execute XSS attacks in\napplications that attempt to sanitize input HTML before rendering.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42506","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://github.com/golang/go/issues/79571","https://go.dev/cl/781700","https://go.dev/issue/79571","https://pkg.go.dev/vuln/GO-2026-5025"],"bugs":[""],"patches":{"golang-golang-x-net-dev":[]},"tags":{},"packages":[{"name":"golang-golang-x-net-dev","source":"https://ubuntu.com/security/cve?package=golang-golang-x-net-dev","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-golang-x-net-dev","debian":"https://tracker.debian.org/pkg/golang-golang-x-net-dev","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42502","published":"2026-05-22T16:16:00","updated_at":"2026-05-27T19:16:31.452854+00:00","description":"\nParsing arbitrary HTML which is then rendered using Render can result in an\nunexpected HTML tree. This can be leveraged to execute XSS attacks in\napplications that attempt to sanitize input HTML before rendering.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42502","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://github.com/golang/go/issues/79572","https://go.dev/cl/781701","https://go.dev/issue/79572","https://pkg.go.dev/vuln/GO-2026-5027"],"bugs":[""],"patches":{"golang-golang-x-net-dev":[]},"tags":{},"packages":[{"name":"golang-golang-x-net-dev","source":"https://ubuntu.com/security/cve?package=golang-golang-x-net-dev","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-golang-x-net-dev","debian":"https://tracker.debian.org/pkg/golang-golang-x-net-dev","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-39821","published":"2026-05-22T16:16:00","updated_at":"2026-06-09T19:58:11.183901+00:00","description":"\nThe ToASCII and ToUnicode functions incorrectly accept Punycode-encoded\nlabels that decode to an ASCII-only label. For example,\nToUnicode(\"xn--example-.com\") incorrectly returns the name \"example.com\"\nrather than an error. This behavior can lead to privilege escalation in\nprograms using the idna package. For example, a program which performs\nprivilege checks on the ASCII hostname may reject \"example.com\" but permit\n\"xn--example-.com\". If that program subsequently converts the ASCII\nhostname to Unicode, it will inadvertently permits access to the Unicode\nname \"example.com\".","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39821","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://github.com/golang/go/issues/78760","https://go.dev/cl/767220","https://go.dev/issue/78760","https://pkg.go.dev/vuln/GO-2026-5026","https://ubuntu.com/security/notices/USN-8416-1"],"bugs":[""],"patches":{"golang-golang-x-net-dev":["upstream: https://github.com/golang/net/commit/8c4c965e028475082408749b50ed7a686df0d265"]},"tags":{},"packages":[{"name":"golang-golang-x-net-dev","source":"https://ubuntu.com/security/cve?package=golang-golang-x-net-dev","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-golang-x-net-dev","debian":"https://tracker.debian.org/pkg/golang-golang-x-net-dev","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"not-affected","description":"0.55.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8416-1"],"notices":[{"id":"USN-8416-1","title":"Go Networking vulnerability","summary":"Go Networking could allow unintended access to network services.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-09T18:01:10.757574","description":"It was discovered that Go Networking incorrectly handled certain\nPunycode-encoded labels in the idna package. An attacker could possibly use\nthis issue to bypass hostname-based access restrictions.","is_hidden":false,"release_packages":{"bionic":[{"name":"golang-golang-x-net-dev","version":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3","description":"Supplementary Go networking development files","is_source":true},{"name":"golang-go.net-dev","version":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-golang-x-net-dev","version_link":null,"pocket":"esm-apps"},{"name":"golang-golang-x-net-dev","version":"1:0.0+git20170629.c81e7f2+dfsg-2ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-golang-x-net-dev","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"golang-golang-x-net-dev","version":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3","description":"Supplementary Go networking development files","is_source":true},{"name":"golang-go.net-dev","version":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-golang-x-net-dev","version_link":null,"pocket":"esm-apps"},{"name":"golang-golang-x-net-dev","version":"1:0.0+git20190811.74dc4d7+dfsg-1ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/golang-golang-x-net-dev","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-39821"]}]},{"id":"CVE-2026-27136","published":"2026-05-22T16:16:00","updated_at":"2026-05-27T19:15:40.036332+00:00","description":"\nParsing arbitrary HTML which is then rendered using Render can result in an\nunexpected HTML tree. This can be leveraged to execute XSS attacks in\napplications that attempt to sanitize input HTML before rendering.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-27136","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://github.com/golang/go/issues/79575","https://go.dev/cl/781685","https://go.dev/issue/79575","https://pkg.go.dev/vuln/GO-2026-5030"],"bugs":[""],"patches":{"golang-golang-x-net-dev":[]},"tags":{},"packages":[{"name":"golang-golang-x-net-dev","source":"https://ubuntu.com/security/cve?package=golang-golang-x-net-dev","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-golang-x-net-dev","debian":"https://tracker.debian.org/pkg/golang-golang-x-net-dev","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25681","published":"2026-05-22T16:16:00","updated_at":"2026-05-27T19:15:40.036332+00:00","description":"\nParsing arbitrary HTML which is then rendered using Render can result in an\nunexpected HTML tree. This can be leveraged to execute XSS attacks in\napplications that attempt to sanitize input HTML before rendering.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25681","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://github.com/golang/go/issues/79574","https://go.dev/cl/781703","https://go.dev/issue/79574","https://pkg.go.dev/vuln/GO-2026-5029"],"bugs":[""],"patches":{"golang-golang-x-net-dev":[]},"tags":{},"packages":[{"name":"golang-golang-x-net-dev","source":"https://ubuntu.com/security/cve?package=golang-golang-x-net-dev","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-golang-x-net-dev","debian":"https://tracker.debian.org/pkg/golang-golang-x-net-dev","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25680","published":"2026-05-22T16:16:00","updated_at":"2026-05-27T19:16:04.569823+00:00","description":"\nParsing arbitrary HTML can consume excessive CPU time, possibly leading to\ndenial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25680","https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8","https://github.com/golang/go/issues/79573","https://go.dev/cl/781702","https://go.dev/issue/79573","https://pkg.go.dev/vuln/GO-2026-5028"],"bugs":[""],"patches":{"golang-golang-x-net-dev":[]},"tags":{},"packages":[{"name":"golang-golang-x-net-dev","source":"https://ubuntu.com/security/cve?package=golang-golang-x-net-dev","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-golang-x-net-dev","debian":"https://tracker.debian.org/pkg/golang-golang-x-net-dev","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9256","published":"2026-05-22T15:16:00","updated_at":"2026-06-06T04:10:34.245188+00:00","description":"\nNGINX Plus and NGINX Open Source have a vulnerability in the\nngx_http_rewrite_module module. This vulnerability exists when a rewrite\ndirective uses a regex pattern with distinct, overlapping Perl-Compatible\nRegular Expression (PCRE) captures (for example, ^/((.*))$) and a\nreplacement string that references multiple such captures (for example,\n$1$2) in a redirect or arguments context. An unauthenticated attacker along\nwith conditions beyond their control can exploit this vulnerability by\nsending crafted HTTP requests. This may cause a heap buffer overflow in the\nNGINX worker process leading to a restart. Additionally, attackers can\nexecute code on systems with Address Space Layout Randomization (ASLR)\ndisabled or when the attacker can bypass ASLR.\nNote: Software versions which have reached End of Technical Support (EoTS)\nare not evaluated.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":9.2,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9256","https://my.f5.com/manage/s/article/K000161377","http://www.openwall.com/lists/oss-security/2026/05/22/14","https://ubuntu.com/security/notices/USN-8354-1","https://ubuntu.com/security/notices/USN-8375-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137339"],"patches":{"nginx":["upstream: https://github.com/nginx/nginx/commit/3f135ae2eb60ce376196c898a6c7cb4d774f7068"]},"tags":{},"packages":[{"name":"nginx","source":"https://ubuntu.com/security/cve?package=nginx","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nginx","debian":"https://tracker.debian.org/pkg/nginx","statuses":[{"release_codename":"upstream","status":"released","description":"1.30.1-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.14.0-0ubuntu1.11+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.18.0-0ubuntu1.7+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"1.18.0-6ubuntu14.12","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.0-2ubuntu7.9","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.28.0-6ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.28.3-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.4.6-1ubuntu3.9+esm6","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.10.3-0ubuntu0.16.04.5+esm7","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8354-1","USN-8375-1"],"notices":[{"id":"USN-8354-1","title":"nginx vulnerabilities","summary":"Several security issues were fixed in nginx.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-01T13:52:07.100084","description":"It was discovered that nginx did not properly validate source addresses in\nthe HTTP/3 QUIC module. A remote attacker could possibly use this issue to\nbypass authorization checks or rate limiting. This issue only affected\nUbuntu 25.04 and Ubuntu 25.10. (CVE-2026-40460)\n\nIt was discovered that nginx contained a use-after-free vulnerability in\nthe ngx_http_ssl_module module when client certificate verification and\nOCSP validation were enabled. A remote attacker could use this issue to\ncause nginx to crash, resulting in a denial of service, or possibly modify\ndata in memory. (CVE-2026-40701)\n\nIt was discovered that nginx did not properly handle certain proxied\nresponses in the ngx_http_charset_module module. A remote attacker could\npossibly use this issue to obtain sensitive information or cause nginx to\ncrash, resulting in a denial of service. (CVE-2026-42934)\n\nIt was discovered that nginx did not properly process certain SCGI and\nuWSGI responses. An attacker able to perform a machine-in-the-middle attack\ncould possibly use this issue to obtain sensitive information or cause\nnginx to crash, resulting in a denial of service. (CVE-2026-42946)\n\nIt was discovered that nginx incorrectly handled certain rewrite rules in\nthe ngx_http_rewrite_module module. A remote attacker could use this issue\nto cause nginx to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-9256)","is_hidden":false,"release_packages":{"jammy":[{"name":"nginx","version":"1.18.0-6ubuntu14.12","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-cache-purge","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-dav-ext","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-echo","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-fancyindex","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-geoip","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-geoip2","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-ndk","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-subs-filter","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-uploadprogress","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-upstream-fair","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-nchan","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-rtmp","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"libnginx-mod-stream-geoip2","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"nginx","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"nginx-common","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"nginx-core","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"nginx-doc","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"nginx-extras","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"nginx-full","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"},{"name":"nginx-light","version":"1.18.0-6ubuntu14.12","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.18.0-6ubuntu14.12","pocket":"security"}],"noble":[{"name":"nginx","version":"1.24.0-2ubuntu7.9","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-geoip","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"nginx","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"nginx-common","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"nginx-core","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"nginx-dev","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"nginx-doc","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"nginx-extras","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"nginx-full","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"},{"name":"nginx-light","version":"1.24.0-2ubuntu7.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.24.0-2ubuntu7.9","pocket":"security"}],"questing":[{"name":"nginx","version":"1.28.0-6ubuntu1.4","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-geoip","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"nginx","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"nginx-common","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"nginx-core","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"nginx-dev","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"nginx-doc","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"nginx-extras","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"nginx-full","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"},{"name":"nginx-light","version":"1.28.0-6ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.0-6ubuntu1.4","pocket":"security"}],"resolute":[{"name":"nginx","version":"1.28.3-2ubuntu1.2","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-geoip","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"libnginx-mod-http-image-filter","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"libnginx-mod-http-perl","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"libnginx-mod-http-xslt-filter","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"libnginx-mod-mail","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"libnginx-mod-stream","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"libnginx-mod-stream-geoip","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"nginx","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"nginx-common","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"nginx-core","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"nginx-dev","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"nginx-doc","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"nginx-extras","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"nginx-full","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"},{"name":"nginx-light","version":"1.28.3-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":"https://launchpad.net/ubuntu/+source/nginx/1.28.3-2ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-9256","CVE-2026-40460","CVE-2026-40701","CVE-2026-42946","CVE-2026-42934"]},{"id":"USN-8375-1","title":"nginx vulnerabilities","summary":"Several security issues were fixed in nginx.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-03T07:11:56.067229","description":"It was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain memory operations when doing SMTP authentication. This\ncould possibly result in sensitive information being sent to the\nauthentication server. (CVE-2025-53859)\n\nIt was discovered that nginx incorrectly handled proxying to upstream TLS\nservers. An attacker could possibly use this issue to insert plain text\ndata into the response from an upstream proxied server. (CVE-2026-1642)\n\nIt was discovered that the nginx ngx_mail_auth_http_module module\nincorrectly handled certain requests. An attacker could possibly use this\nissue to cause nginx to crash, resulting in a denial of service.\n(CVE-2026-27651)\n\nIt was discovered that the nginx ngx_http_dav_module module incorrectly\nhandled certain destination URIs. An attacker could use this issue to cause\nnginx to crash, resulting in a denial of service, or possibly modify source\nor destination names outside of the document root. (CVE-2026-27654)\n\nIt was discovered that the nginx ngx_http_mp4_module module incorrectly\nhandled certain MP4 files. An attacker could use this issue to cause nginx\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2026-27784, CVE-2026-32647)\n\nIt was discovered that the nginx ngx_mail_smtp_module module incorrectly\nhandled certain CRLF sequences. An attacker could possibly use this issue\nto inject arbitrary SMTP headers. (CVE-2026-28753)\n\nIt was discovered that nginx contained a use-after-free vulnerability in\nthe ngx_http_ssl_module module when client certificate verification and\nOCSP validation were enabled. A remote attacker could use this issue to\ncause nginx to crash, resulting in a denial of service, or possibly modify\ndata in memory. (CVE-2026-40701)\n\nIt was discovered that nginx did not properly handle certain proxied\nresponses in the ngx_http_charset_module module. A remote attacker could\npossibly use this issue to obtain sensitive information or cause nginx to\ncrash, resulting in a denial of service. (CVE-2026-42934)\n\nIt was discovered that the nginx ngx_http_rewrite_module component\nincorrectly handled certain rewrite directives. A remote attacker could use\nthis issue to cause nginx to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-42945)\n\nIt was discovered that nginx did not properly process certain SCGI and\nuWSGI responses. An attacker able to perform a machine-in-the-middle attack\ncould possibly use this issue to obtain sensitive information or cause\nnginx to crash, resulting in a denial of service. (CVE-2026-42946)\n\nIt was discovered that nginx incorrectly handled certain rewrite rules in\nthe ngx_http_rewrite_module module. A remote attacker could use this issue\nto cause nginx to crash, resulting in a denial of service, or possibly\nexecute arbitrary code. (CVE-2026-9256)","is_hidden":false,"release_packages":{"bionic":[{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.14.0-0ubuntu1.11+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"libnginx-mod-http-auth-pam","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-cache-purge","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-dav-ext","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-echo","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-fancyindex","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-geoip2","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-headers-more-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-image-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-lua","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-ndk","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-perl","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-subs-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-uploadprogress","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-upstream-fair","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-http-xslt-filter","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-mail","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-nchan","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-rtmp","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"libnginx-mod-stream","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-common","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-core","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-doc","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-extras","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-full","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"},{"name":"nginx-light","version":"1.18.0-0ubuntu1.7+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-naxsi-ui","version":"1.4.6-1ubuntu3.9+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","description":"small, powerful, scalable web/proxy server","is_source":true},{"name":"nginx","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-common","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-core","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-doc","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-extras","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-full","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"},{"name":"nginx-light","version":"1.10.3-0ubuntu0.16.04.5+esm7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/nginx","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-1642","CVE-2026-27654","CVE-2026-9256","CVE-2026-27651","CVE-2026-32647","CVE-2025-53859","CVE-2026-27784","CVE-2026-42934","CVE-2026-42946","CVE-2026-42945","CVE-2026-28753","CVE-2026-40701"]}]},{"id":"CVE-2026-9277","published":"2026-05-22T14:16:00","updated_at":"2026-06-09T10:51:54.186297+00:00","description":"\nshell-quote's `quote()` function did not validate object-token inputs\nagainst the operator model used by `parse()`. The `.op` field was\nbackslash-escaped character by character using `/(.)/g`, which in\nJavaScript does not match line terminators (\\n, \\r, U+2028, U+2029). A line\nterminator in `.op` therefore passed through unescaped into the output;\nPOSIX shells treat a literal newline as a command separator, so any content\nafter it would execute as a second command. The vulnerable code path is\nreachable in two ways: (1) direct construction of `{ op: '...\\n...' }` from\nexternal input, and (2) via `parse(cmd, envFn)` when `envFn` returns object\ntokens whose `.op` is attacker-influenced. Both are documented API surface.\nFixed by replacing the per-character escape with strict shape validation:\n`.op` must match the parser's control-operator allowlist; `{ op: 'glob',\npattern }` validates `pattern` and forbids line terminators; `{ comment }`\nvalidates `comment` and forbids line terminators; any other object shape\nthrows `TypeError`.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":9.2,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9277","https://github.com/ljharb/shell-quote/security/advisories/GHSA-w7jw-789q-3m8p","https://github.com/ljharb/shell-quote","https://github.com/ljharb/shell-quote/commit/1518179","https://www.npmjs.com/package/shell-quote","http://www.openwall.com/lists/oss-security/2026/05/23/2","https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d","https://ubuntu.com/security/notices/USN-8410-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137372"],"patches":{"node-shell-quote":["upstream: https://github.com/ljharb/shell-quote/commit/4378a6e613db5948168684864e49b42b83134d2d"]},"tags":{},"packages":[{"name":"node-shell-quote","source":"https://ubuntu.com/security/cve?package=node-shell-quote","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=node-shell-quote","debian":"https://tracker.debian.org/pkg/node-shell-quote","statuses":[{"release_codename":"upstream","status":"released","description":"1.8.4+~1.7.5-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.6.1+20160617-git72fb5a8ce29b-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1.7.3+~1.7.1-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1.7.4+~1.7.1-1ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.7.4+~1.7.1-1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.8.3+~1.7.5-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8410-1"],"notices":[{"id":"USN-8410-1","title":"shell-quote vulnerability","summary":"shell-quote could be made to crash or run programs as your login if it\nreceived specially crafted input.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-09T08:38:23.785593","description":"Akshat Sinha discovered that shell-quote improperly validated object-token\ninputs. An attacker could possibly use this issue to cause shell-quote to\ncrash, resulting in a denial of service, or execute arbitrary code.","is_hidden":false,"release_packages":{"bionic":[{"name":"node-shell-quote","version":"1.6.1+20160617-git72fb5a8ce29b-1ubuntu0.1~esm1","description":"Parse and quote shell commands","is_source":true},{"name":"node-shell-quote","version":"1.6.1+20160617-git72fb5a8ce29b-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/node-shell-quote","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"node-shell-quote","version":"1.7.3+~1.7.1-1ubuntu0.1~esm1","description":"Parse and quote shell commands","is_source":true},{"name":"node-shell-quote","version":"1.7.3+~1.7.1-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/node-shell-quote","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"node-shell-quote","version":"1.7.4+~1.7.1-1ubuntu0.24.04.1","description":"Parse and quote shell commands","is_source":true},{"name":"node-shell-quote","version":"1.7.4+~1.7.1-1ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/node-shell-quote","version_link":"https://launchpad.net/ubuntu/+source/node-shell-quote/1.7.4+~1.7.1-1ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"node-shell-quote","version":"1.7.4+~1.7.1-1ubuntu0.25.10.1","description":"Parse and quote shell commands","is_source":true},{"name":"node-shell-quote","version":"1.7.4+~1.7.1-1ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/node-shell-quote","version_link":"https://launchpad.net/ubuntu/+source/node-shell-quote/1.7.4+~1.7.1-1ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"node-shell-quote","version":"1.8.3+~1.7.5-1ubuntu0.1~esm1","description":"Parse and quote shell commands","is_source":true},{"name":"node-shell-quote","version":"1.8.3+~1.7.5-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/node-shell-quote","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-9277"]}]},{"id":"CVE-2026-8997","published":"2026-05-22T14:16:00","updated_at":"2026-07-10T21:24:46.545847+00:00","description":"\nvifm is vulnerable to a heap buffer overflow during the history merge\nprocess when saving the state file (vifminfo.json). This flaw occurs\nbecause the application lacks a runtime check on the length of history\nentries in release builds, potentially allowing a crafted long path or\ncommand in the history to cause memory corruption or application crashes.\nReleases from 0.12.1 to 0.14.3 (including) are considered vulnerable. This\nissue was fixed in commit 23063c7","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8997","https://cert.pl/en/posts/2026/05/CVE-2026-8997","https://github.com/vifm/vifm/commit/23063c741f15a85621fd232dfc3ac5b779f6910d"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137528"],"patches":{"vifm":[]},"tags":{},"packages":[{"name":"vifm","source":"https://ubuntu.com/security/cve?package=vifm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=vifm","debian":"https://tracker.debian.org/pkg/vifm","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46598","published":"2026-05-22T00:00:00","updated_at":"2026-05-27T19:19:20.983888+00:00","description":"\nFor certain crafted inputs, a 'ed25519.PrivateKey' was created by casting\nmalformed wire bytes, leading to a panic when used.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46598","https://go.dev/issue/79596","https://go.dev/cl/781360","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5033"],"bugs":[""],"patches":{"golang-go.crypto":[],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46597","published":"2026-05-22T00:00:00","updated_at":"2026-05-27T19:19:48.461593+00:00","description":"\nAn incorrectly placed cast from bytes to int allowed for server-side panic\nin the AES-GCM packet decoder for well-crafted inputs.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46597","https://go.dev/issue/79561","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://go.dev/cl/781620","https://pkg.go.dev/vuln/GO-2026-5013"],"bugs":[""],"patches":{"golang-go.crypto":[],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46595","published":"2026-05-22T00:00:00","updated_at":"2026-06-26T00:54:46.322161+00:00","description":"\nPreviously, CVE-2024-45337 fixed an authorization bypass for misused ssh\nserver configurations; if any other type of callback is passed other than\npublic key, then the source-address validation would be skipped.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto\nOn noble and below, this CVE does not affect the package as\nVerifiedPublicKeyCallback has not been introduced at that time. The\nremaining case is covered by CVE-2024-45337."},{"author":"shishir","note":"VerifiedPublicKeyCallback feature only added on 0.43"}],"codename":null,"priority":"medium","cvss3":10.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":10.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46595","https://go.dev/issue/79570","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://go.dev/cl/781642","https://pkg.go.dev/vuln/GO-2026-5023","https://github.com/golang/crypto/commit/533fb3f7e4a5ae23f69d1837cd851d35ff5b76ce","https://ubuntu.com/security/notices/USN-8447-1","https://ubuntu.com/security/notices/USN-8447-3"],"bugs":[""],"patches":{"golang-go.crypto":["upstream: https://github.com/golang/crypto/commit/533fb3f7e4a5ae23f69d1837cd851d35ff5b76ce"],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:0.47.0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.52.0","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"20250116.00-0ubuntu1~24.04.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"20250506.01-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"20250506.01-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8447-3"],"notices":[{"id":"USN-8447-3","title":"Google Guest Agent vulnerabilities","summary":"Several security issues were fixed in Google Guest Agent.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-22T17:23:26.256172","description":"USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides\nthe corresponding updates for Go Cryptography code embedded in Google\nGuest Agent.\n\nOriginal advisory details:\n\n It was discovered that Go Cryptography did not properly handle SSH global\n request responses. A remote attacker could possibly use this issue to cause\n a denial of service. (CVE-2026-39830)\n\n It was discovered that Go Cryptography did not properly verify user\n presence when using FIDO/U2F security keys. An attacker could possibly use\n this issue to bypass user presence verification for hardware security keys.\n This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\n LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831)\n\n It was discovered that Go Cryptography did not properly serialize SSH agent\n key constraint extensions. An attacker could possibly use this issue to\n bypass intended key usage restrictions. This issue only affected Ubuntu\n 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n (CVE-2026-39832)\n\n It was discovered that Go Cryptography did not properly enforce the\n confirm-before-use constraint in the SSH agent keyring. An attacker could\n possibly use this issue to use SSH keys without the required user\n confirmation. (CVE-2026-39833)\n\n It was discovered that Go Cryptography had an integer overflow when\n handling large SSH channel writes. A remote attacker could possibly use\n this issue to cause a denial of service. (CVE-2026-39834)\n\n It was discovered that Go Cryptography did not properly check certificate\n authority key revocation. An attacker could possibly use this issue to\n bypass certificate authority revocation checks. This issue only affected\n Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\n Ubuntu 26.04 LTS. (CVE-2026-42508)\n\n It was discovered that Go Cryptography did not properly enforce the source-\n address critical option for all SSH server callback types. An attacker\n could possibly use this issue to bypass source address authorization\n restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595)","is_hidden":false,"release_packages":{"bionic":[{"name":"google-guest-agent","version":"20241011.01-0ubuntu1~18.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20241011.01-0ubuntu1~18.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~20.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~20.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~22.04.3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~22.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~22.04.3","pocket":"security"}],"noble":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~24.04.4","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~24.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~24.04.4","pocket":"security"}],"questing":[{"name":"google-guest-agent","version":"20250506.01-0ubuntu1.2","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250506.01-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu1.2","pocket":"security"}],"resolute":[{"name":"google-guest-agent","version":"20250506.01-0ubuntu2.1","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250506.01-0ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu2.1","pocket":"security"}],"xenial":[{"name":"google-guest-agent","version":"20240716.00-0ubuntu1~16.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20240716.00-0ubuntu1~16.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-39831","CVE-2026-39834","CVE-2026-39830","CVE-2026-46595"]}]},{"id":"CVE-2026-42784","published":"2026-05-22T00:00:00","updated_at":"2026-09-18T09:01:54.819397+00:00","description":"\n[openpgp: Don&#x27;t imply missing key flags from key type]","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42784"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137328"],"patches":{"rust-sequoia-openpgp":[]},"tags":{},"packages":[{"name":"rust-sequoia-openpgp","source":"https://ubuntu.com/security/cve?package=rust-sequoia-openpgp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rust-sequoia-openpgp","debian":"https://tracker.debian.org/pkg/rust-sequoia-openpgp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42508","published":"2026-05-22T00:00:00","updated_at":"2026-06-19T12:32:14.361641+00:00","description":"\nPreviously, a revoked 'SignatureKey' belonging to a CA was not correctly\nchecked for revocation. Now, both the 'key' and 'key.SignatureKey' are\nchecked for @revoked.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42508","https://go.dev/issue/79568","https://go.dev/cl/781220","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5021","https://github.com/golang/crypto/commit/f717e29698a271c548239ed56bf5dd9516d6f7e8","https://ubuntu.com/security/notices/USN-8447-1","https://ubuntu.com/security/notices/USN-8447-2"],"bugs":[""],"patches":{"golang-go.crypto":["upstream: https://github.com/golang/crypto/commit/f717e29698a271c548239ed56bf5dd9516d6f7e8"],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"focal","status":"released","description":"1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1:0.0~git20211202.5770296-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1:0.19.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"1:0.47.0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.52.0","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"bionic","status":"released","description":"3.0.3-0ubuntu1~18.04.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2.0.11-0ubuntu1~16.04.4+esm3","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8447-2"],"notices":[{"id":"USN-8447-2","title":"LXD vulnerabilities","summary":"Several security issues were fixed in LXD.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-18T20:05:09.969191","description":"USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides\nthe corresponding updates for Go Cryptography code embedded in LXD for\nCVE-2026-39830, CVE-2026-39833, CVE-2026-39834, and CVE-2026-42508.\n\nOriginal advisory details:\n\n It was discovered that Go Cryptography did not properly handle SSH global\n request responses. A remote attacker could possibly use this issue to cause\n a denial of service. (CVE-2026-39830)\n\n It was discovered that Go Cryptography did not properly verify user\n presence when using FIDO/U2F security keys. An attacker could possibly use\n this issue to bypass user presence verification for hardware security keys.\n This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\n LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831)\n\n It was discovered that Go Cryptography did not properly serialize SSH agent\n key constraint extensions. An attacker could possibly use this issue to\n bypass intended key usage restrictions. This issue only affected Ubuntu\n 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n (CVE-2026-39832)\n\n It was discovered that Go Cryptography did not properly enforce the\n confirm-before-use constraint in the SSH agent keyring. An attacker could\n possibly use this issue to use SSH keys without the required user\n confirmation. (CVE-2026-39833)\n\n It was discovered that Go Cryptography had an integer overflow when\n handling large SSH channel writes. A remote attacker could possibly use\n this issue to cause a denial of service. (CVE-2026-39834)\n\n It was discovered that Go Cryptography did not properly check certificate\n authority key revocation. An attacker could possibly use this issue to\n bypass certificate authority revocation checks. This issue only affected\n Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\n Ubuntu 26.04 LTS. (CVE-2026-42508)\n\n It was discovered that Go Cryptography did not properly enforce the source-\n address critical option for all SSH server callback types. An attacker\n could possibly use this issue to bypass source address authorization\n restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595)","is_hidden":false,"release_packages":{"bionic":[{"name":"lxd","version":"3.0.3-0ubuntu1~18.04.2+esm3","description":"Container hypervisor based on LXC","is_source":true},{"name":"lxd","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"},{"name":"lxd-client","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"},{"name":"lxd-tools","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"lxd","version":"2.0.11-0ubuntu1~16.04.4+esm3","description":"Container hypervisor based on LXC","is_source":true},{"name":"golang-github-lxc-lxd-dev","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxc2","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd-client","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd-tools","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-39830","CVE-2026-39833","CVE-2026-39834","CVE-2026-42508"]}]},{"id":"CVE-2026-39835","published":"2026-05-22T00:00:00","updated_at":"2026-05-27T19:16:31.452854+00:00","description":"\nSSH servers which use CertChecker as a public key callback without setting\nIsUserAuthority or IsHostAuthority could be caused to panic by a client\npresenting a certificate. CertChecker now returns an error instead of\npanicking when these callbacks are nil.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39835","https://go.dev/issue/79563","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://go.dev/cl/781660","https://pkg.go.dev/vuln/GO-2026-5015"],"bugs":[""],"patches":{"golang-go.crypto":[],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-39834","published":"2026-05-22T00:00:00","updated_at":"2026-06-26T00:54:46.322161+00:00","description":"\nWhen writing data larger than 4GB in a single Write call on an SSH channel,\nan integer overflow in the internal payload size calculation caused the\nwrite loop to spin indefinitely, sending empty packets without making\nprogress. The size comparison now uses int64 to prevent truncation.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39834","https://go.dev/issue/79567","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://go.dev/cl/781663","https://pkg.go.dev/vuln/GO-2026-5020","https://github.com/golang/crypto/commit/e052873987615dc96fe67607a9a6adb76311344f","https://ubuntu.com/security/notices/USN-8447-1","https://ubuntu.com/security/notices/USN-8447-2","https://ubuntu.com/security/notices/USN-8447-3"],"bugs":[""],"patches":{"golang-go.crypto":["upstream: https://github.com/golang/crypto/commit/e052873987615dc96fe67607a9a6adb76311344f"],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"bionic","status":"released","description":"1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1:0.0~git20211202.5770296-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1:0.19.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"1:0.47.0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.52.0","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"bionic","status":"released","description":"3.0.3-0ubuntu1~18.04.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2.0.11-0ubuntu1~16.04.4+esm3","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"bionic","status":"released","description":"20241011.01-0ubuntu1~18.04.0+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"20250116.00-0ubuntu1~20.04.0+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"20250116.00-0ubuntu1~22.04.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"20250116.00-0ubuntu1~24.04.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"20250506.01-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"20250506.01-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"20240716.00-0ubuntu1~16.04.0+esm3","component":null,"pocket":"esm-apps-legacy"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8447-2","USN-8447-3"],"notices":[{"id":"USN-8447-2","title":"LXD vulnerabilities","summary":"Several security issues were fixed in LXD.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-18T20:05:09.969191","description":"USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides\nthe corresponding updates for Go Cryptography code embedded in LXD for\nCVE-2026-39830, CVE-2026-39833, CVE-2026-39834, and CVE-2026-42508.\n\nOriginal advisory details:\n\n It was discovered that Go Cryptography did not properly handle SSH global\n request responses. A remote attacker could possibly use this issue to cause\n a denial of service. (CVE-2026-39830)\n\n It was discovered that Go Cryptography did not properly verify user\n presence when using FIDO/U2F security keys. An attacker could possibly use\n this issue to bypass user presence verification for hardware security keys.\n This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\n LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831)\n\n It was discovered that Go Cryptography did not properly serialize SSH agent\n key constraint extensions. An attacker could possibly use this issue to\n bypass intended key usage restrictions. This issue only affected Ubuntu\n 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n (CVE-2026-39832)\n\n It was discovered that Go Cryptography did not properly enforce the\n confirm-before-use constraint in the SSH agent keyring. An attacker could\n possibly use this issue to use SSH keys without the required user\n confirmation. (CVE-2026-39833)\n\n It was discovered that Go Cryptography had an integer overflow when\n handling large SSH channel writes. A remote attacker could possibly use\n this issue to cause a denial of service. (CVE-2026-39834)\n\n It was discovered that Go Cryptography did not properly check certificate\n authority key revocation. An attacker could possibly use this issue to\n bypass certificate authority revocation checks. This issue only affected\n Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\n Ubuntu 26.04 LTS. (CVE-2026-42508)\n\n It was discovered that Go Cryptography did not properly enforce the source-\n address critical option for all SSH server callback types. An attacker\n could possibly use this issue to bypass source address authorization\n restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595)","is_hidden":false,"release_packages":{"bionic":[{"name":"lxd","version":"3.0.3-0ubuntu1~18.04.2+esm3","description":"Container hypervisor based on LXC","is_source":true},{"name":"lxd","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"},{"name":"lxd-client","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"},{"name":"lxd-tools","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"lxd","version":"2.0.11-0ubuntu1~16.04.4+esm3","description":"Container hypervisor based on LXC","is_source":true},{"name":"golang-github-lxc-lxd-dev","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxc2","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd-client","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd-tools","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-39830","CVE-2026-39833","CVE-2026-39834","CVE-2026-42508"]},{"id":"USN-8447-3","title":"Google Guest Agent vulnerabilities","summary":"Several security issues were fixed in Google Guest Agent.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-22T17:23:26.256172","description":"USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides\nthe corresponding updates for Go Cryptography code embedded in Google\nGuest Agent.\n\nOriginal advisory details:\n\n It was discovered that Go Cryptography did not properly handle SSH global\n request responses. A remote attacker could possibly use this issue to cause\n a denial of service. (CVE-2026-39830)\n\n It was discovered that Go Cryptography did not properly verify user\n presence when using FIDO/U2F security keys. An attacker could possibly use\n this issue to bypass user presence verification for hardware security keys.\n This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\n LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831)\n\n It was discovered that Go Cryptography did not properly serialize SSH agent\n key constraint extensions. An attacker could possibly use this issue to\n bypass intended key usage restrictions. This issue only affected Ubuntu\n 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n (CVE-2026-39832)\n\n It was discovered that Go Cryptography did not properly enforce the\n confirm-before-use constraint in the SSH agent keyring. An attacker could\n possibly use this issue to use SSH keys without the required user\n confirmation. (CVE-2026-39833)\n\n It was discovered that Go Cryptography had an integer overflow when\n handling large SSH channel writes. A remote attacker could possibly use\n this issue to cause a denial of service. (CVE-2026-39834)\n\n It was discovered that Go Cryptography did not properly check certificate\n authority key revocation. An attacker could possibly use this issue to\n bypass certificate authority revocation checks. This issue only affected\n Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\n Ubuntu 26.04 LTS. (CVE-2026-42508)\n\n It was discovered that Go Cryptography did not properly enforce the source-\n address critical option for all SSH server callback types. An attacker\n could possibly use this issue to bypass source address authorization\n restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595)","is_hidden":false,"release_packages":{"bionic":[{"name":"google-guest-agent","version":"20241011.01-0ubuntu1~18.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20241011.01-0ubuntu1~18.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~20.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~20.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~22.04.3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~22.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~22.04.3","pocket":"security"}],"noble":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~24.04.4","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~24.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~24.04.4","pocket":"security"}],"questing":[{"name":"google-guest-agent","version":"20250506.01-0ubuntu1.2","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250506.01-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu1.2","pocket":"security"}],"resolute":[{"name":"google-guest-agent","version":"20250506.01-0ubuntu2.1","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250506.01-0ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu2.1","pocket":"security"}],"xenial":[{"name":"google-guest-agent","version":"20240716.00-0ubuntu1~16.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20240716.00-0ubuntu1~16.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-39831","CVE-2026-39834","CVE-2026-39830","CVE-2026-46595"]}]},{"id":"CVE-2026-39833","published":"2026-05-22T00:00:00","updated_at":"2026-06-19T12:32:14.361641+00:00","description":"\nThe in-memory keyring returned by NewKeyring() silently accepted keys with\nthe ConfirmBeforeUse constraint but never enforced it. The key would sign\nwithout any confirmation prompt, with no indication to the caller that the\nconstraint was not in effect. NewKeyring() now returns an error when\nunsupported constraints are requested.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39833","https://go.dev/issue/79436","https://go.dev/cl/778640","https://go.dev/cl/778641","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5005","https://github.com/golang/crypto/commit/0fb843a472225645e917c84f1f9744757f0bab14","https://ubuntu.com/security/notices/USN-8447-1","https://ubuntu.com/security/notices/USN-8447-2"],"bugs":[""],"patches":{"golang-go.crypto":["upstream: https://github.com/golang/crypto/commit/0fb843a472225645e917c84f1f9744757f0bab14"],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"bionic","status":"released","description":"1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1:0.0~git20211202.5770296-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1:0.19.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"1:0.47.0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.52.0","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"bionic","status":"released","description":"3.0.3-0ubuntu1~18.04.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2.0.11-0ubuntu1~16.04.4+esm3","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8447-2"],"notices":[{"id":"USN-8447-2","title":"LXD vulnerabilities","summary":"Several security issues were fixed in LXD.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-18T20:05:09.969191","description":"USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides\nthe corresponding updates for Go Cryptography code embedded in LXD for\nCVE-2026-39830, CVE-2026-39833, CVE-2026-39834, and CVE-2026-42508.\n\nOriginal advisory details:\n\n It was discovered that Go Cryptography did not properly handle SSH global\n request responses. A remote attacker could possibly use this issue to cause\n a denial of service. (CVE-2026-39830)\n\n It was discovered that Go Cryptography did not properly verify user\n presence when using FIDO/U2F security keys. An attacker could possibly use\n this issue to bypass user presence verification for hardware security keys.\n This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\n LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831)\n\n It was discovered that Go Cryptography did not properly serialize SSH agent\n key constraint extensions. An attacker could possibly use this issue to\n bypass intended key usage restrictions. This issue only affected Ubuntu\n 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n (CVE-2026-39832)\n\n It was discovered that Go Cryptography did not properly enforce the\n confirm-before-use constraint in the SSH agent keyring. An attacker could\n possibly use this issue to use SSH keys without the required user\n confirmation. (CVE-2026-39833)\n\n It was discovered that Go Cryptography had an integer overflow when\n handling large SSH channel writes. A remote attacker could possibly use\n this issue to cause a denial of service. (CVE-2026-39834)\n\n It was discovered that Go Cryptography did not properly check certificate\n authority key revocation. An attacker could possibly use this issue to\n bypass certificate authority revocation checks. This issue only affected\n Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\n Ubuntu 26.04 LTS. (CVE-2026-42508)\n\n It was discovered that Go Cryptography did not properly enforce the source-\n address critical option for all SSH server callback types. An attacker\n could possibly use this issue to bypass source address authorization\n restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595)","is_hidden":false,"release_packages":{"bionic":[{"name":"lxd","version":"3.0.3-0ubuntu1~18.04.2+esm3","description":"Container hypervisor based on LXC","is_source":true},{"name":"lxd","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"},{"name":"lxd-client","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"},{"name":"lxd-tools","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"lxd","version":"2.0.11-0ubuntu1~16.04.4+esm3","description":"Container hypervisor based on LXC","is_source":true},{"name":"golang-github-lxc-lxd-dev","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxc2","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd-client","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd-tools","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-39830","CVE-2026-39833","CVE-2026-39834","CVE-2026-42508"]}]},{"id":"CVE-2026-39832","published":"2026-05-22T00:00:00","updated_at":"2026-06-19T12:32:14.361641+00:00","description":"\nWhen adding a key to a remote agent constraint extensions such as\nrestrict-destination-v00@openssh.com were not serialized in the request.\nDestination restrictions were silently stripped when forwarding keys,\nallowing unrestricted use of the key on the remote host. The client now\nserializes all constraint extensions. Additionally, the in-memory keyring\nreturned by NewKeyring() now rejects keys with unsupported constraint\nextensions instead of silently ignoring them.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"},{"author":"shishir","note":"constraint extensions feature introduced in focal, bionic and below\nare not affected"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39832","https://go.dev/issue/79435","https://go.dev/cl/778642","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://pkg.go.dev/vuln/GO-2026-5006","https://github.com/golang/crypto/commit/e3d1254f1e7e60baa086142c46174bf6d8d0fe50","https://ubuntu.com/security/notices/USN-8447-1"],"bugs":[""],"patches":{"golang-go.crypto":["upstream: https://github.com/golang/crypto/commit/e3d1254f1e7e60baa086142c46174bf6d8d0fe50"],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1:0.0~git20211202.5770296-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1:0.19.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"1:0.47.0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.52.0","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-39831","published":"2026-05-22T00:00:00","updated_at":"2026-06-26T00:54:46.322161+00:00","description":"\nThe Verify() method for FIDO/U2F security key types\n(sk-ecdsa-sha2-nistp256@openssh.com, sk-ssh-ed25519@openssh.com) did not\ncheck the User Presence flag. Signatures generated without physical touch\nwere accepted, allowing unattended use of a hardware security key. To\nrestore the previous behavior, return a \"no-touch-required\" extension in\nPermissions.Extensions from PublicKeyCallback.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"},{"author":"shishir","note":"fido/u2f support introduced only in focal, earlier releases are\nnot affected"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39831","https://go.dev/issue/79566","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://go.dev/cl/781662","https://pkg.go.dev/vuln/GO-2026-5019","https://github.com/golang/crypto/commit/b61cf853a89d82cad68da5e12a6beca2116f8456","https://ubuntu.com/security/notices/USN-8447-1","https://ubuntu.com/security/notices/USN-8447-3"],"bugs":[""],"patches":{"golang-go.crypto":["upstream: https://github.com/golang/crypto/commit/b61cf853a89d82cad68da5e12a6beca2116f8456"],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1:0.0~git20211202.5770296-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1:0.19.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"1:0.47.0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.52.0","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"bionic","status":"released","description":"20241011.01-0ubuntu1~18.04.0+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"20250116.00-0ubuntu1~20.04.0+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"20250116.00-0ubuntu1~22.04.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"20250116.00-0ubuntu1~24.04.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"20250506.01-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"20250506.01-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"20240716.00-0ubuntu1~16.04.0+esm3","component":null,"pocket":"esm-apps-legacy"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8447-3"],"notices":[{"id":"USN-8447-3","title":"Google Guest Agent vulnerabilities","summary":"Several security issues were fixed in Google Guest Agent.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-22T17:23:26.256172","description":"USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides\nthe corresponding updates for Go Cryptography code embedded in Google\nGuest Agent.\n\nOriginal advisory details:\n\n It was discovered that Go Cryptography did not properly handle SSH global\n request responses. A remote attacker could possibly use this issue to cause\n a denial of service. (CVE-2026-39830)\n\n It was discovered that Go Cryptography did not properly verify user\n presence when using FIDO/U2F security keys. An attacker could possibly use\n this issue to bypass user presence verification for hardware security keys.\n This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\n LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831)\n\n It was discovered that Go Cryptography did not properly serialize SSH agent\n key constraint extensions. An attacker could possibly use this issue to\n bypass intended key usage restrictions. This issue only affected Ubuntu\n 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n (CVE-2026-39832)\n\n It was discovered that Go Cryptography did not properly enforce the\n confirm-before-use constraint in the SSH agent keyring. An attacker could\n possibly use this issue to use SSH keys without the required user\n confirmation. (CVE-2026-39833)\n\n It was discovered that Go Cryptography had an integer overflow when\n handling large SSH channel writes. A remote attacker could possibly use\n this issue to cause a denial of service. (CVE-2026-39834)\n\n It was discovered that Go Cryptography did not properly check certificate\n authority key revocation. An attacker could possibly use this issue to\n bypass certificate authority revocation checks. This issue only affected\n Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\n Ubuntu 26.04 LTS. (CVE-2026-42508)\n\n It was discovered that Go Cryptography did not properly enforce the source-\n address critical option for all SSH server callback types. An attacker\n could possibly use this issue to bypass source address authorization\n restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595)","is_hidden":false,"release_packages":{"bionic":[{"name":"google-guest-agent","version":"20241011.01-0ubuntu1~18.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20241011.01-0ubuntu1~18.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~20.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~20.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~22.04.3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~22.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~22.04.3","pocket":"security"}],"noble":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~24.04.4","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~24.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~24.04.4","pocket":"security"}],"questing":[{"name":"google-guest-agent","version":"20250506.01-0ubuntu1.2","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250506.01-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu1.2","pocket":"security"}],"resolute":[{"name":"google-guest-agent","version":"20250506.01-0ubuntu2.1","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250506.01-0ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu2.1","pocket":"security"}],"xenial":[{"name":"google-guest-agent","version":"20240716.00-0ubuntu1~16.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20240716.00-0ubuntu1~16.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-39831","CVE-2026-39834","CVE-2026-39830","CVE-2026-46595"]}]},{"id":"CVE-2026-39830","published":"2026-05-22T00:00:00","updated_at":"2026-06-26T00:54:46.322161+00:00","description":"\nA malicious SSH peer could send unsolicited global request responses to\nfill an internal buffer, blocking the connection's read loop. The blocked\ngoroutine could not be released by calling Close(), resulting in a resource\nleak per connection. Unsolicited global responses are now discarded.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"}],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-39830","https://go.dev/issue/79564","https://groups.google.com/g/golang-announce/c/a082jnz-LvI","https://go.dev/cl/781640","https://go.dev/cl/781664","https://pkg.go.dev/vuln/GO-2026-5017","https://github.com/golang/crypto/commit/4e7a7384ecbc8d519f6f4c11b36fa9d761fc8946","https://ubuntu.com/security/notices/USN-8447-1","https://ubuntu.com/security/notices/USN-8447-2","https://ubuntu.com/security/notices/USN-8447-3"],"bugs":[""],"patches":{"golang-go.crypto":["upstream: https://github.com/golang/crypto/commit/4e7a7384ecbc8d519f6f4c11b36fa9d761fc8946"],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"bionic","status":"released","description":"1:0.0~git20170629.0.5ef0053-2ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1:0.0~git20200221.2aa609c-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1:0.0~git20211202.5770296-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1:0.19.0-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"1:0.47.0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"xenial","status":"released","description":"1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.52.0","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"bionic","status":"released","description":"3.0.3-0ubuntu1~18.04.2+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2.0.11-0ubuntu1~16.04.4+esm3","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"bionic","status":"released","description":"20241011.01-0ubuntu1~18.04.0+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"20250116.00-0ubuntu1~20.04.0+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"20250116.00-0ubuntu1~22.04.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"20250116.00-0ubuntu1~24.04.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"20250506.01-0ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"20250506.01-0ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"20240716.00-0ubuntu1~16.04.0+esm3","component":null,"pocket":"esm-apps-legacy"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8447-2","USN-8447-3"],"notices":[{"id":"USN-8447-2","title":"LXD vulnerabilities","summary":"Several security issues were fixed in LXD.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-18T20:05:09.969191","description":"USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides\nthe corresponding updates for Go Cryptography code embedded in LXD for\nCVE-2026-39830, CVE-2026-39833, CVE-2026-39834, and CVE-2026-42508.\n\nOriginal advisory details:\n\n It was discovered that Go Cryptography did not properly handle SSH global\n request responses. A remote attacker could possibly use this issue to cause\n a denial of service. (CVE-2026-39830)\n\n It was discovered that Go Cryptography did not properly verify user\n presence when using FIDO/U2F security keys. An attacker could possibly use\n this issue to bypass user presence verification for hardware security keys.\n This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\n LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831)\n\n It was discovered that Go Cryptography did not properly serialize SSH agent\n key constraint extensions. An attacker could possibly use this issue to\n bypass intended key usage restrictions. This issue only affected Ubuntu\n 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n (CVE-2026-39832)\n\n It was discovered that Go Cryptography did not properly enforce the\n confirm-before-use constraint in the SSH agent keyring. An attacker could\n possibly use this issue to use SSH keys without the required user\n confirmation. (CVE-2026-39833)\n\n It was discovered that Go Cryptography had an integer overflow when\n handling large SSH channel writes. A remote attacker could possibly use\n this issue to cause a denial of service. (CVE-2026-39834)\n\n It was discovered that Go Cryptography did not properly check certificate\n authority key revocation. An attacker could possibly use this issue to\n bypass certificate authority revocation checks. This issue only affected\n Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\n Ubuntu 26.04 LTS. (CVE-2026-42508)\n\n It was discovered that Go Cryptography did not properly enforce the source-\n address critical option for all SSH server callback types. An attacker\n could possibly use this issue to bypass source address authorization\n restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595)","is_hidden":false,"release_packages":{"bionic":[{"name":"lxd","version":"3.0.3-0ubuntu1~18.04.2+esm3","description":"Container hypervisor based on LXC","is_source":true},{"name":"lxd","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"},{"name":"lxd-client","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"},{"name":"lxd-tools","version":"3.0.3-0ubuntu1~18.04.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"lxd","version":"2.0.11-0ubuntu1~16.04.4+esm3","description":"Container hypervisor based on LXC","is_source":true},{"name":"golang-github-lxc-lxd-dev","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxc2","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd-client","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"},{"name":"lxd-tools","version":"2.0.11-0ubuntu1~16.04.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/lxd","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-39830","CVE-2026-39833","CVE-2026-39834","CVE-2026-42508"]},{"id":"USN-8447-3","title":"Google Guest Agent vulnerabilities","summary":"Several security issues were fixed in Google Guest Agent.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-22T17:23:26.256172","description":"USN-8447-1 fixed vulnerabilities in Go Cryptography. This update provides\nthe corresponding updates for Go Cryptography code embedded in Google\nGuest Agent.\n\nOriginal advisory details:\n\n It was discovered that Go Cryptography did not properly handle SSH global\n request responses. A remote attacker could possibly use this issue to cause\n a denial of service. (CVE-2026-39830)\n\n It was discovered that Go Cryptography did not properly verify user\n presence when using FIDO/U2F security keys. An attacker could possibly use\n this issue to bypass user presence verification for hardware security keys.\n This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04\n LTS, and Ubuntu 26.04 LTS. (CVE-2026-39831)\n\n It was discovered that Go Cryptography did not properly serialize SSH agent\n key constraint extensions. An attacker could possibly use this issue to\n bypass intended key usage restrictions. This issue only affected Ubuntu\n 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n (CVE-2026-39832)\n\n It was discovered that Go Cryptography did not properly enforce the\n confirm-before-use constraint in the SSH agent keyring. An attacker could\n possibly use this issue to use SSH keys without the required user\n confirmation. (CVE-2026-39833)\n\n It was discovered that Go Cryptography had an integer overflow when\n handling large SSH channel writes. A remote attacker could possibly use\n this issue to cause a denial of service. (CVE-2026-39834)\n\n It was discovered that Go Cryptography did not properly check certificate\n authority key revocation. An attacker could possibly use this issue to\n bypass certificate authority revocation checks. This issue only affected\n Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\n Ubuntu 26.04 LTS. (CVE-2026-42508)\n\n It was discovered that Go Cryptography did not properly enforce the source-\n address critical option for all SSH server callback types. An attacker\n could possibly use this issue to bypass source address authorization\n restrictions. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-46595)","is_hidden":false,"release_packages":{"bionic":[{"name":"google-guest-agent","version":"20241011.01-0ubuntu1~18.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20241011.01-0ubuntu1~18.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~20.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~20.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~22.04.3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~22.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~22.04.3","pocket":"security"}],"noble":[{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~24.04.4","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250116.00-0ubuntu1~24.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250116.00-0ubuntu1~24.04.4","pocket":"security"}],"questing":[{"name":"google-guest-agent","version":"20250506.01-0ubuntu1.2","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250506.01-0ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu1.2","pocket":"security"}],"resolute":[{"name":"google-guest-agent","version":"20250506.01-0ubuntu2.1","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20250506.01-0ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":"https://launchpad.net/ubuntu/+source/google-guest-agent/20250506.01-0ubuntu2.1","pocket":"security"}],"xenial":[{"name":"google-guest-agent","version":"20240716.00-0ubuntu1~16.04.0+esm3","description":"Google Compute Engine Guest Agent","is_source":true},{"name":"google-guest-agent","version":"20240716.00-0ubuntu1~16.04.0+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/google-guest-agent","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-39831","CVE-2026-39834","CVE-2026-39830","CVE-2026-46595"]}]}],"offset":11320,"limit":20,"total_results":79316}