{"cves":[{"id":"CVE-2026-8632","published":"2026-05-20T21:16:00","updated_at":"2026-06-30T18:04:31.521362+00:00","description":"\nA potential security vulnerability has been identified in the HP Linux\nImaging and Printing Software. This potential vulnerability may allow\nescalation of privileges and/or arbitrary code execution via operating\nsystem command injection.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8632","https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118","https://ubuntu.com/security/notices/USN-8483-1"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137374"],"patches":{"hplip":[]},"tags":{},"packages":[{"name":"hplip","source":"https://ubuntu.com/security/cve?package=hplip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hplip","debian":"https://tracker.debian.org/pkg/hplip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.26.4+dfsg0-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.21.12+dfsg0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.23.12+dfsg0-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.24.4+dfsg0-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.24.4+dfsg0-0ubuntu8.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8483-1"],"notices":[{"id":"USN-8483-1","title":"HPLIP vulnerabilities","summary":"Several security issues were fixed in HPLIP.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-30T11:33:09.572246","description":"It was discovered that HPLIP incorrectly handled certain print data. An\nattacker could possibly use this issue to cause HPLIP to execute arbitrary\ncode. (CVE-2026-8631)\n\nIt was discovered that HPLIP incorrectly handled certain inputs. A local\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-8632)","is_hidden":false,"release_packages":{"jammy":[{"name":"hplip","version":"3.21.12+dfsg0-1ubuntu0.1","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hpijs-ppds","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"hplip","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"hplip-data","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"hplip-doc","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"hplip-gui","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"libhpmud-dev","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"libhpmud0","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"libsane-hpaio","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"printer-driver-hpcups","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"printer-driver-hpijs","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"printer-driver-postscript-hp","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"}],"noble":[{"name":"hplip","version":"3.23.12+dfsg0-0ubuntu5.1","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hpijs-ppds","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"hplip","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"hplip-data","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"hplip-doc","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"hplip-gui","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"libhpmud-dev","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"libhpmud0","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"libsane-hpaio","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"printer-driver-hpcups","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"printer-driver-hpijs","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"printer-driver-postscript-hp","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"}],"questing":[{"name":"hplip","version":"3.24.4+dfsg0-0ubuntu5.2","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hpijs-ppds","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"hplip","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"hplip-data","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"hplip-doc","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"hplip-gui","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"libhpmud-dev","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"libhpmud0","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"libsane-hpaio","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"printer-driver-hpcups","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"printer-driver-hpijs","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"printer-driver-postscript-hp","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"}],"resolute":[{"name":"hplip","version":"3.24.4+dfsg0-0ubuntu8.1","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hpijs-ppds","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"hplip","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"hplip-data","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"hplip-doc","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"hplip-gui","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"libhpmud-dev","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"libhpmud0","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"libsane-hpaio","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"printer-driver-hpcups","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"printer-driver-hpijs","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"printer-driver-postscript-hp","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-8632","CVE-2026-8631"]}]},{"id":"CVE-2026-8631","published":"2026-05-20T21:16:00","updated_at":"2026-06-30T18:04:31.521362+00:00","description":"\nA potential security vulnerability has been identified in the HP Linux\nImaging and Printing Software. This potential vulnerability may allow\nescalation of privileges and/or arbitrary code execution via an integer\noverflow in the hpcups processing path when handling crafted print data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":9.3,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8631","https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118","https://ubuntu.com/security/notices/USN-8483-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137374"],"patches":{"hplip":[]},"tags":{},"packages":[{"name":"hplip","source":"https://ubuntu.com/security/cve?package=hplip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=hplip","debian":"https://tracker.debian.org/pkg/hplip","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.26.4+dfsg0-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.21.12+dfsg0-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.23.12+dfsg0-0ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.24.4+dfsg0-0ubuntu5.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.24.4+dfsg0-0ubuntu8.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8483-1"],"notices":[{"id":"USN-8483-1","title":"HPLIP vulnerabilities","summary":"Several security issues were fixed in HPLIP.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-30T11:33:09.572246","description":"It was discovered that HPLIP incorrectly handled certain print data. An\nattacker could possibly use this issue to cause HPLIP to execute arbitrary\ncode. (CVE-2026-8631)\n\nIt was discovered that HPLIP incorrectly handled certain inputs. A local\nattacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-8632)","is_hidden":false,"release_packages":{"jammy":[{"name":"hplip","version":"3.21.12+dfsg0-1ubuntu0.1","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hpijs-ppds","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"hplip","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"hplip-data","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"hplip-doc","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"hplip-gui","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"libhpmud-dev","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"libhpmud0","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"libsane-hpaio","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"printer-driver-hpcups","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"printer-driver-hpijs","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"},{"name":"printer-driver-postscript-hp","version":"3.21.12+dfsg0-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.21.12+dfsg0-1ubuntu0.1","pocket":"security"}],"noble":[{"name":"hplip","version":"3.23.12+dfsg0-0ubuntu5.1","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hpijs-ppds","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"hplip","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"hplip-data","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"hplip-doc","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"hplip-gui","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"libhpmud-dev","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"libhpmud0","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"libsane-hpaio","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"printer-driver-hpcups","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"printer-driver-hpijs","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"},{"name":"printer-driver-postscript-hp","version":"3.23.12+dfsg0-0ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.23.12+dfsg0-0ubuntu5.1","pocket":"security"}],"questing":[{"name":"hplip","version":"3.24.4+dfsg0-0ubuntu5.2","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hpijs-ppds","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"hplip","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"hplip-data","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"hplip-doc","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"hplip-gui","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"libhpmud-dev","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"libhpmud0","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"libsane-hpaio","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"printer-driver-hpcups","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"printer-driver-hpijs","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"},{"name":"printer-driver-postscript-hp","version":"3.24.4+dfsg0-0ubuntu5.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu5.2","pocket":"security"}],"resolute":[{"name":"hplip","version":"3.24.4+dfsg0-0ubuntu8.1","description":"HP Linux Printing and Imaging System (HPLIP)","is_source":true},{"name":"hpijs-ppds","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"hplip","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"hplip-data","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"hplip-doc","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"hplip-gui","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"libhpmud-dev","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"libhpmud0","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"libsane-hpaio","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"printer-driver-hpcups","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"printer-driver-hpijs","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"},{"name":"printer-driver-postscript-hp","version":"3.24.4+dfsg0-0ubuntu8.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hplip","version_link":"https://launchpad.net/ubuntu/+source/hplip/3.24.4+dfsg0-0ubuntu8.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-8632","CVE-2026-8631"]}]},{"id":"CVE-2026-47373","published":"2026-05-20T21:16:00","updated_at":"2026-05-27T19:19:48.461593+00:00","description":"\nCrypt::SaltedHash versions through 0.09 for Perl is susceptible to timing\nattacks.\nThese versions use Perl's built-in eq comparison. Discrepencies in timing\ncould be used to guess the underlying hash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-47373","https://lists.security.metacpan.org/cve-announce/msg/40249915/","https://github.com/robrwo/perl-Crypt-SaltedHash/commit/c07bfc5c23185b0667233d0f2e1252d81f1f027a.patch","https://metacpan.org/release/RRWO/Crypt-SaltedHash-0.10/changes","http://www.openwall.com/lists/oss-security/2026/05/20/21"],"bugs":[""],"patches":{"libcrypt-saltedhash-perl":[]},"tags":{},"packages":[{"name":"libcrypt-saltedhash-perl","source":"https://ubuntu.com/security/cve?package=libcrypt-saltedhash-perl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libcrypt-saltedhash-perl","debian":"https://tracker.debian.org/pkg/libcrypt-saltedhash-perl","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9126","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:20:13.684894+00:00","description":"\nUse after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a\nremote attacker to execute arbitrary code inside a sandbox via a crafted\nHTML page. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9126","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/496280532"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9124","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:19:20.983888+00:00","description":"\nInsufficient validation of untrusted input in Input in Google Chrome on\nprior to 148.0.7778.179 allowed a remote attacker who had compromised the\nrenderer process to leak cross-origin data via a crafted HTML page.\n(Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9124","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/496375695"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9123","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:19:48.461593+00:00","description":"\nHeap buffer overflow in Chromecast in Google Chrome on Android, Linux,\nChromeOS prior to 148.0.7778.179 allowed a local attacker to execute\narbitrary code inside a sandbox via malicious network traffic. (Chromium\nsecurity severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9123","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/495988507"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9122","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:19:48.461593+00:00","description":"\nOut of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179\nallowed a remote attacker to obtain potentially sensitive information from\nprocess memory via a crafted HTML page. (Chromium security severity:\nMedium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9122","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/489579953"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9121","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:20:13.684894+00:00","description":"\nOut of bounds read in GPU in Google Chrome on prior to 148.0.7778.179\nallowed a remote attacker to potentially exploit heap corruption via a\ncrafted HTML page. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9121","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/488064108"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9120","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:19:20.983888+00:00","description":"\nUse after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a\nremote attacker to execute arbitrary code via a crafted HTML page.\n(Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9120","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/504620824"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9119","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:19:48.461593+00:00","description":"\nHeap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179\nallowed a remote attacker to execute arbitrary code inside a sandbox via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9119","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/502661101"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9118","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:20:13.684894+00:00","description":"\nUse after free in XR in Google Chrome on Windows prior to 148.0.7778.179\nallowed a remote attacker to execute arbitrary code via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9118","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/498702233"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9117","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:20:13.684894+00:00","description":"\nType Confusion in GFX in Google Chrome on Linux, ChromeOS prior to\n148.0.7778.179 allowed a remote attacker who had compromised the renderer\nprocess to potentially perform a sandbox escape via a crafted video file.\n(Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9117","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/497542537"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9116","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:19:20.983888+00:00","description":"\nInsufficient policy enforcement in ServiceWorker in Google Chrome on prior\nto 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9116","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/497436273"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9115","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:19:48.461593+00:00","description":"\nInsufficient policy enforcement in Service Worker in Google Chrome on prior\nto 148.0.7778.179 allowed a remote attacker to bypass same origin policy\nvia a crafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9115","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/495999481"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9114","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:20:13.684894+00:00","description":"\nUse after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed\na remote attacker to execute arbitrary code inside a sandbox via malicious\nnetwork traffic. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9114","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/495798630"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9113","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:19:48.461593+00:00","description":"\nOut of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179\nallowed a remote attacker to perform an out of bounds memory read via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9113","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/489585044"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9112","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:20:13.684894+00:00","description":"\nUse after free in GPU in Google Chrome on Windows prior to 148.0.7778.179\nallowed a remote attacker to execute arbitrary code inside a sandbox via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9112","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/489791425"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9111","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:20:13.684894+00:00","description":"\nUse after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179\nallowed a remote attacker to execute arbitrary code via a crafted HTML\npage. (Chromium security severity: Critical)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9111","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/504551032"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9110","published":"2026-05-20T20:16:00","updated_at":"2026-05-27T19:19:20.983888+00:00","description":"\nInappropriate implementation in UI in Google Chrome on Windows prior to\n148.0.7778.179 allowed a remote attacker who had compromised the renderer\nprocess to perform UI spoofing via a crafted HTML page. (Chromium security\nseverity: Critical)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":4.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9110","https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html","https://issues.chromium.org/issues/503551154"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-9100","published":"2026-05-20T17:16:00","updated_at":"2026-07-10T21:24:46.545847+00:00","description":"\nThe MongoDB C Driver's legacy GridFS API accepts malformed file metadata\nfrom the database without adequate validation. Crafted documents in a\nGridFS collection may cause any application that reads those files via the\nlegacy API to either crash (via a division-by-zero) or silently leak\nprocess memory contents (via an out-of-bounds read).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-9100","https://jira.mongodb.org/browse/CDRIVER-6281"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137217"],"patches":{"mongo-c-driver":[]},"tags":{},"packages":[{"name":"mongo-c-driver","source":"https://ubuntu.com/security/cve?package=mongo-c-driver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongo-c-driver","debian":"https://tracker.debian.org/pkg/mongo-c-driver","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.4-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":11400,"limit":20,"total_results":79316}