{"cves":[{"id":"CVE-2026-43909","published":"2026-05-14T20:17:00","updated_at":"2026-06-18T19:33:18.814546+00:00","description":"\nOpenImageIO is a toolset for reading, writing, and manipulating image files\nof any image file format relevant to VFX / animation. Prior to 3.0.18.0 and\n3.1.13.0, a signed 32-bit integer overflow in the loop index expression i *\n4 inside SwapRGBABytes() causes the function to compute a large negative\npointer offset when processing kABGR DPX images with large dimensions. The\nimmediate crash is an out-of-bounds read (the memcpy at line 45 reads from\n&input[i * 4] first), but the subsequent write operations at lines 46–49\ntarget the same wrapped offset — making this a combined OOB read+write\nprimitive. This vulnerability is fixed in 3.0.18.0 and 3.1.13.0.","ubuntu_description":"","notes":[{"author":"elisehdy","note":"openimageio in jammy is currently FTBFS due to OpenVDB/oneTBB namespace conflict; fix deferred pending resolution."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43909","https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-g267-j53j-5258"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openvdb/+bug/1970108"],"patches":{"openimageio":["upstream: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/e086aa86bc5ac6c3a7fb0f5059db4dcde02b9572"]},"tags":{},"packages":[{"name":"openimageio","source":"https://ubuntu.com/security/cve?package=openimageio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openimageio","debian":"https://tracker.debian.org/pkg/openimageio","statuses":[{"release_codename":"bionic","status":"released","description":"1.7.17~dfsg0-1ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"deferred","description":"see note","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"2.5.19.1+dfsg-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"released","description":"3.0.18.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.11~dfsg0-1ubuntu1+esm2","component":null,"pocket":"esm-apps-legacy"}]}],"notices_ids":["USN-8438-1"],"notices":[{"id":"USN-8438-1","title":"OpenImageIO vulnerabilities","summary":"Several security issues were fixed in OpenImageIO.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-16T21:02:47.040684","description":"It was discovered that OpenImageIO incorrectly performed bounds\nchecking when processing SGI files. An attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary\ncode. (CVE-2026-43903)\n\nIt was discovered that OpenImageIO incorrectly handled run-length\nencoding when processing Softimage PIC files. An attacker\ncould possibly use this issue to cause a denial of service or\nexecute arbitrary code. (CVE-2026-43904)\n\nIt was discovered that OpenImageIO incorrectly validated subimage\nmetadata when processing HEIF files. An attacker could\npossibly use this issue to cause a denial of service or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu\n24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-43906)\n\nIt was discovered that OpenImageIO contained multiple integer\noverflow vulnerabilities when processing DPX files. An\nattacker could possibly use these issues to cause a denial of\nservice or execute arbitrary code. (CVE-2026-43907, CVE-2026-43908,\nCVE-2026-43909)","is_hidden":false,"release_packages":{"bionic":[{"name":"openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio1.7","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python-openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.1","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.4t64","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.5","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio-doc","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio1.6","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"openimageio-tools","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"python-openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-43903","CVE-2026-43906","CVE-2026-43907","CVE-2026-43908","CVE-2026-43904","CVE-2026-43909"]}]},{"id":"CVE-2026-43908","published":"2026-05-14T20:17:00","updated_at":"2026-06-18T19:33:18.814546+00:00","description":"\nOpenImageIO is a toolset for reading, writing, and manipulating image files\nof any image file format relevant to VFX / animation. Prior to 3.0.18.0 and\n3.1.13.0, a signed 32-bit integer overflow in the pixel-loop index\nexpression i * 3 inside ConvertCbYCrYToRGB() causes the function to compute\na large negative pointer offset into the output buffer, producing an\nout-of-bounds write that crashes the process. This vulnerability is fixed\nin 3.0.18.0 and 3.1.13.0.","ubuntu_description":"","notes":[{"author":"elisehdy","note":"openimageio in jammy is currently FTBFS due to OpenVDB/oneTBB namespace conflict; fix deferred pending resolution."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43908","https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-2jr5-q49v-3858"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openvdb/+bug/1970108"],"patches":{"openimageio":["upstream: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/e086aa86bc5ac6c3a7fb0f5059db4dcde02b9572"]},"tags":{},"packages":[{"name":"openimageio","source":"https://ubuntu.com/security/cve?package=openimageio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openimageio","debian":"https://tracker.debian.org/pkg/openimageio","statuses":[{"release_codename":"bionic","status":"released","description":"1.7.17~dfsg0-1ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"deferred","description":"see note","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"2.5.19.1+dfsg-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"released","description":"3.0.18.0","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.11~dfsg0-1ubuntu1+esm2","component":null,"pocket":"esm-apps-legacy"}]}],"notices_ids":["USN-8438-1"],"notices":[{"id":"USN-8438-1","title":"OpenImageIO vulnerabilities","summary":"Several security issues were fixed in OpenImageIO.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-16T21:02:47.040684","description":"It was discovered that OpenImageIO incorrectly performed bounds\nchecking when processing SGI files. An attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary\ncode. (CVE-2026-43903)\n\nIt was discovered that OpenImageIO incorrectly handled run-length\nencoding when processing Softimage PIC files. An attacker\ncould possibly use this issue to cause a denial of service or\nexecute arbitrary code. (CVE-2026-43904)\n\nIt was discovered that OpenImageIO incorrectly validated subimage\nmetadata when processing HEIF files. An attacker could\npossibly use this issue to cause a denial of service or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu\n24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-43906)\n\nIt was discovered that OpenImageIO contained multiple integer\noverflow vulnerabilities when processing DPX files. An\nattacker could possibly use these issues to cause a denial of\nservice or execute arbitrary code. (CVE-2026-43907, CVE-2026-43908,\nCVE-2026-43909)","is_hidden":false,"release_packages":{"bionic":[{"name":"openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio1.7","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python-openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.1","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.4t64","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.5","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio-doc","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio1.6","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"openimageio-tools","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"python-openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-43903","CVE-2026-43906","CVE-2026-43907","CVE-2026-43908","CVE-2026-43904","CVE-2026-43909"]}]},{"id":"CVE-2026-43907","published":"2026-05-14T20:17:00","updated_at":"2026-06-18T19:33:18.814546+00:00","description":"\nOpenImageIO is a toolset for reading, writing, and manipulating image files\nof any image file format relevant to VFX / animation. Prior to 3.0.18.0 and\n3.1.13.0, a signed integer overflow in QueryRGBBufferSizeInternal() in\nDPXColorConverter.cpp leads to a heap-based out-of-bounds write when\nprocessing crafted DPX image files. The function computes buffer sizes\nusing 32-bit signed integer arithmetic with negative multipliers (e.g.,\npixels * -3 * bytes for kCbYCr descriptors and pixels * -4 * bytes for\nkABGR descriptors), where a negative result is used as an in-band signal\nthat no separate buffer is needed. When the pixel count is sufficiently\nlarge, the multiplication overflows INT_MIN and wraps to a small positive\nvalue. The caller in dpxinput.cpp interprets this positive value as a\nrequired buffer size, allocates an undersized heap buffer via\nm_decodebuf.resize(), and then writes the full image data into it via\nfread, resulting in a heap buffer overflow. An attacker can exploit this by\ncrafting a DPX file that triggers the overflow, causing a denial of service\n(crash) or potentially arbitrary code execution through heap corruption in\nany application that reads pixel data using OpenImageIO. This vulnerability\nis fixed in 3.0.18.0 and 3.1.13.0.","ubuntu_description":"","notes":[{"author":"elisehdy","note":"openimageio in jammy is currently FTBFS due to OpenVDB/oneTBB namespace conflict; fix deferred pending resolution."}],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43907","https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-cq46-hp4h-cvfr"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openvdb/+bug/1970108"],"patches":{"openimageio":["upstream: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/e086aa86bc5ac6c3a7fb0f5059db4dcde02b9572"]},"tags":{},"packages":[{"name":"openimageio","source":"https://ubuntu.com/security/cve?package=openimageio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openimageio","debian":"https://tracker.debian.org/pkg/openimageio","statuses":[{"release_codename":"bionic","status":"released","description":"1.7.17~dfsg0-1ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"deferred","description":"see note","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"2.5.19.1+dfsg-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"released","description":"3.0.18.0","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.11~dfsg0-1ubuntu1+esm2","component":null,"pocket":"esm-apps-legacy"}]}],"notices_ids":["USN-8438-1"],"notices":[{"id":"USN-8438-1","title":"OpenImageIO vulnerabilities","summary":"Several security issues were fixed in OpenImageIO.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-16T21:02:47.040684","description":"It was discovered that OpenImageIO incorrectly performed bounds\nchecking when processing SGI files. An attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary\ncode. (CVE-2026-43903)\n\nIt was discovered that OpenImageIO incorrectly handled run-length\nencoding when processing Softimage PIC files. An attacker\ncould possibly use this issue to cause a denial of service or\nexecute arbitrary code. (CVE-2026-43904)\n\nIt was discovered that OpenImageIO incorrectly validated subimage\nmetadata when processing HEIF files. An attacker could\npossibly use this issue to cause a denial of service or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu\n24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-43906)\n\nIt was discovered that OpenImageIO contained multiple integer\noverflow vulnerabilities when processing DPX files. An\nattacker could possibly use these issues to cause a denial of\nservice or execute arbitrary code. (CVE-2026-43907, CVE-2026-43908,\nCVE-2026-43909)","is_hidden":false,"release_packages":{"bionic":[{"name":"openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio1.7","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python-openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.1","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.4t64","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.5","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio-doc","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio1.6","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"openimageio-tools","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"python-openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-43903","CVE-2026-43906","CVE-2026-43907","CVE-2026-43908","CVE-2026-43904","CVE-2026-43909"]}]},{"id":"CVE-2026-43906","published":"2026-05-14T20:17:00","updated_at":"2026-06-18T19:33:18.814546+00:00","description":"\nOpenImageIO is a toolset for reading, writing, and manipulating image files\nof any image file format relevant to VFX / animation. Prior to 3.0.18.0 and\n3.1.13.0, a heap-based buffer overflow in the HEIF decoder of OpenImageIO\nallows out-of-bounds writes via crafted images due to a subimage metadata\nmismatch, leading to memory corruption and potential code execution. This\nvulnerability is fixed in 3.0.18.0 and 3.1.13.0.","ubuntu_description":"","notes":[{"author":"elisehdy","note":"openimageio in jammy is currently FTBFS due to OpenVDB/oneTBB namespace conflict; fix deferred pending resolution."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43906","https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-gmrp-x952-3m66"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openvdb/+bug/1970108"],"patches":{"openimageio":["upstream: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/a2beff4270aa5dc6b324befdc3b2c8bdbc855638"]},"tags":{},"packages":[{"name":"openimageio","source":"https://ubuntu.com/security/cve?package=openimageio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openimageio","debian":"https://tracker.debian.org/pkg/openimageio","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"deferred","description":"see note","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"2.5.19.1+dfsg-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"released","description":"3.0.18.0","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-8438-1"],"notices":[{"id":"USN-8438-1","title":"OpenImageIO vulnerabilities","summary":"Several security issues were fixed in OpenImageIO.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-16T21:02:47.040684","description":"It was discovered that OpenImageIO incorrectly performed bounds\nchecking when processing SGI files. An attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary\ncode. (CVE-2026-43903)\n\nIt was discovered that OpenImageIO incorrectly handled run-length\nencoding when processing Softimage PIC files. An attacker\ncould possibly use this issue to cause a denial of service or\nexecute arbitrary code. (CVE-2026-43904)\n\nIt was discovered that OpenImageIO incorrectly validated subimage\nmetadata when processing HEIF files. An attacker could\npossibly use this issue to cause a denial of service or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu\n24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-43906)\n\nIt was discovered that OpenImageIO contained multiple integer\noverflow vulnerabilities when processing DPX files. An\nattacker could possibly use these issues to cause a denial of\nservice or execute arbitrary code. (CVE-2026-43907, CVE-2026-43908,\nCVE-2026-43909)","is_hidden":false,"release_packages":{"bionic":[{"name":"openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio1.7","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python-openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.1","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.4t64","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.5","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio-doc","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio1.6","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"openimageio-tools","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"python-openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-43903","CVE-2026-43906","CVE-2026-43907","CVE-2026-43908","CVE-2026-43904","CVE-2026-43909"]}]},{"id":"CVE-2026-43905","published":"2026-05-14T20:17:00","updated_at":"2026-06-18T19:33:18.814546+00:00","description":"\nOpenImageIO is a toolset for reading, writing, and manipulating image files\nof any image file format relevant to VFX / animation. Prior to 3.0.18.0 and\n3.1.13.0, jpeg2000input.cpp:395 computes buffer size as const int bufsize =\nw * h * ch * buffer_bpp using signed 32-bit arithmetic. When the product\nexceeds INT_MAX, the result wraps to 0 or a small value. m_buf.resize()\nallocates an undersized buffer, and subsequent pixel write loops cause heap\noverflow. Conditional on USE_OPENJPH build flag. This vulnerability is\nfixed in 3.0.18.0 and 3.1.13.0.","ubuntu_description":"","notes":[{"author":"elisehdy","note":"Ubuntu builds do not set USE_OPENJPH."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43905","https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-pj45-cf3g-28gq"],"bugs":[""],"patches":{"openimageio":["upstream: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/4ca49d1bda31968503be5fcb76abbc1f51cd03b1"]},"tags":{},"packages":[{"name":"openimageio","source":"https://ubuntu.com/security/cve?package=openimageio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openimageio","debian":"https://tracker.debian.org/pkg/openimageio","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.18.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-43904","published":"2026-05-14T20:17:00","updated_at":"2026-06-18T19:33:18.814546+00:00","description":"\nOpenImageIO is a toolset for reading, writing, and manipulating image files\nof any image file format relevant to VFX / animation. Prior to 3.0.18.0 and\n3.1.13.0, softimageinput.cpp:469 (mixed RLE) and :345 (pure RLE) do not\nclamp the run length to remaining scanline width before writing pixels. The\nraw packet path (line 403) correctly clamps with std::min, but RLE paths\nskip this check. A crafted .pic file causes heap overflow up to 65535\nbytes. This vulnerability is fixed in 3.0.18.0 and 3.1.13.0.","ubuntu_description":"","notes":[{"author":"elisehdy","note":"openimageio in jammy is currently FTBFS due to OpenVDB/oneTBB namespace conflict; fix deferred pending resolution."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43904","https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-4499-j545-7q33"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openvdb/+bug/1970108"],"patches":{"openimageio":["upstream: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/5f6dffefe1e5932f57f602fe7f668fb0949b02d3"]},"tags":{},"packages":[{"name":"openimageio","source":"https://ubuntu.com/security/cve?package=openimageio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openimageio","debian":"https://tracker.debian.org/pkg/openimageio","statuses":[{"release_codename":"bionic","status":"released","description":"1.7.17~dfsg0-1ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"deferred","description":"see note","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"2.5.19.1+dfsg-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"released","description":"3.0.18.0","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.11~dfsg0-1ubuntu1+esm2","component":null,"pocket":"esm-apps-legacy"}]}],"notices_ids":["USN-8438-1"],"notices":[{"id":"USN-8438-1","title":"OpenImageIO vulnerabilities","summary":"Several security issues were fixed in OpenImageIO.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-16T21:02:47.040684","description":"It was discovered that OpenImageIO incorrectly performed bounds\nchecking when processing SGI files. An attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary\ncode. (CVE-2026-43903)\n\nIt was discovered that OpenImageIO incorrectly handled run-length\nencoding when processing Softimage PIC files. An attacker\ncould possibly use this issue to cause a denial of service or\nexecute arbitrary code. (CVE-2026-43904)\n\nIt was discovered that OpenImageIO incorrectly validated subimage\nmetadata when processing HEIF files. An attacker could\npossibly use this issue to cause a denial of service or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu\n24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-43906)\n\nIt was discovered that OpenImageIO contained multiple integer\noverflow vulnerabilities when processing DPX files. An\nattacker could possibly use these issues to cause a denial of\nservice or execute arbitrary code. (CVE-2026-43907, CVE-2026-43908,\nCVE-2026-43909)","is_hidden":false,"release_packages":{"bionic":[{"name":"openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio1.7","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python-openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.1","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.4t64","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.5","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio-doc","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio1.6","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"openimageio-tools","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"python-openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-43903","CVE-2026-43906","CVE-2026-43907","CVE-2026-43908","CVE-2026-43904","CVE-2026-43909"]}]},{"id":"CVE-2026-43903","published":"2026-05-14T20:17:00","updated_at":"2026-06-18T19:33:18.814546+00:00","description":"\nOpenImageIO is a toolset for reading, writing, and manipulating image files\nof any image file format relevant to VFX / animation. Prior to 3.0.18.0 and\n3.1.13.0, sgiinput.cpp:265,274 use OIIO_DASSERT for bounds checking in the\nRLE decode loop. In release builds, OIIO_DASSERT compiles to\n((void)sizeof(x)) (dassert.h:210), making all bounds checks no-ops. A\ncrafted .sgi file with RLE count exceeding scanline width causes heap\nbuffer overflow and crash. This vulnerability is fixed in 3.0.18.0 and\n3.1.13.0.","ubuntu_description":"","notes":[{"author":"elisehdy","note":"openimageio in jammy is currently FTBFS due to OpenVDB/oneTBB namespace conflict; fix deferred pending resolution."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-43903","https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-jg3q-vm3q-2j35"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/openvdb/+bug/1970108"],"patches":{"openimageio":["upstream: https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/9ff6a7d737cc96bd6e719e604f80ad408f9ea742"]},"tags":{},"packages":[{"name":"openimageio","source":"https://ubuntu.com/security/cve?package=openimageio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openimageio","debian":"https://tracker.debian.org/pkg/openimageio","statuses":[{"release_codename":"bionic","status":"released","description":"1.7.17~dfsg0-1ubuntu2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"deferred","description":"see note","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"resolute","status":"released","description":"2.5.19.1+dfsg-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"released","description":"3.0.18.0","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.11~dfsg0-1ubuntu1+esm2","component":null,"pocket":"esm-apps-legacy"}]}],"notices_ids":["USN-8438-1"],"notices":[{"id":"USN-8438-1","title":"OpenImageIO vulnerabilities","summary":"Several security issues were fixed in OpenImageIO.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-16T21:02:47.040684","description":"It was discovered that OpenImageIO incorrectly performed bounds\nchecking when processing SGI files. An attacker could possibly\nuse this issue to cause a denial of service or execute arbitrary\ncode. (CVE-2026-43903)\n\nIt was discovered that OpenImageIO incorrectly handled run-length\nencoding when processing Softimage PIC files. An attacker\ncould possibly use this issue to cause a denial of service or\nexecute arbitrary code. (CVE-2026-43904)\n\nIt was discovered that OpenImageIO incorrectly validated subimage\nmetadata when processing HEIF files. An attacker could\npossibly use this issue to cause a denial of service or execute\narbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu\n24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-43906)\n\nIt was discovered that OpenImageIO contained multiple integer\noverflow vulnerabilities when processing DPX files. An\nattacker could possibly use these issues to cause a denial of\nservice or execute arbitrary code. (CVE-2026-43907, CVE-2026-43908,\nCVE-2026-43909)","is_hidden":false,"release_packages":{"bionic":[{"name":"openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio1.7","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python-openimageio","version":"1.7.17~dfsg0-1ubuntu2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.1","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.1.12.0~dfsg0-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.4t64","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.4.17.0+dfsg-1.1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio-doc","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"libopenimageio2.5","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"openimageio-tools","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"},{"name":"python3-openimageio","version":"2.5.19.1+dfsg-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","description":"Library for reading and writing images","is_source":true},{"name":"libopenimageio-dev","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio-doc","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libopenimageio1.6","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"openimageio-tools","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"},{"name":"python-openimageio","version":"1.6.11~dfsg0-1ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openimageio","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-43903","CVE-2026-43906","CVE-2026-43907","CVE-2026-43908","CVE-2026-43904","CVE-2026-43909"]}]},{"id":"CVE-2026-46470","published":"2026-05-14T18:16:00","updated_at":"2026-05-27T17:48:39.466671+00:00","description":"\nAn issue was discovered in GStreamer gst-plugins-good before 1.28.2. When\nparsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function\ndoes not sufficiently validate atom data before performing division\noperations, leading to denial of service due to integer division by zero.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"same commits as CVE-2026-46469"}],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46470","https://gstreamer.freedesktop.org/security/sa-2026-0018.html","https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11243","https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11243.patch","https://ubuntu.com/security/notices/USN-8317-1"],"bugs":[""],"patches":{"gst-plugins-good1.0":["upstream: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/dbd4cb49e72836d2372de2d2043d28c7a7fce9c4","upstream: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/10fd1abfdb793641b4eb0454478e01fd74648d5c","upstream: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/34418818730bc04e41f512e65331b3f206cb5eb9","upstream: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/dc7ab66ab23a054eaa942071cfb548d47fe4ca2f"]},"tags":{},"packages":[{"name":"gst-plugins-good1.0","source":"https://ubuntu.com/security/cve?package=gst-plugins-good1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gst-plugins-good1.0","debian":"https://tracker.debian.org/pkg/gst-plugins-good1.0","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.28.2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.28.2-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.20.3-0ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.2-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.26.5-1ubuntu2.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-8317-1"],"notices":[{"id":"USN-8317-1","title":"GStreamer Good Plugins vulnerabilities","summary":"Several security issues were fixed in GStreamer Good Plugins.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-27T12:07:51.624281","description":"It was discovered that GStreamer Good Plugins incorrectly handled certain\nMP4 audio tracks. An attacker could possibly use this issue to cause\nGStreamer Good Plugins to crash, resulting in a denial of service.","is_hidden":false,"release_packages":{"jammy":[{"name":"gst-plugins-good1.0","version":"1.20.3-0ubuntu1.6","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"}],"noble":[{"name":"gst-plugins-good1.0","version":"1.24.2-1ubuntu1.4","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"gstreamer1.0-qt6","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"}],"questing":[{"name":"gst-plugins-good1.0","version":"1.26.5-1ubuntu2.3","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"gstreamer1.0-qt6","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46470","CVE-2026-46469"]}]},{"id":"CVE-2026-46469","published":"2026-05-14T18:16:00","updated_at":"2026-05-27T17:46:34.860602+00:00","description":"\nAn issue was discovered in GStreamer gst-plugins-good before 1.28.2. When\nparsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function\ndoes not sufficiently validate atom data before performing division\noperations, leading to denial of service due to integer division by zero.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46469","https://gstreamer.freedesktop.org/security/sa-2026-0018.html","https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11243","https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11243.patch","https://ubuntu.com/security/notices/USN-8317-1"],"bugs":[""],"patches":{"gst-plugins-good1.0":["upstream: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/dbd4cb49e72836d2372de2d2043d28c7a7fce9c4","upstream: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/10fd1abfdb793641b4eb0454478e01fd74648d5c","upstream: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/34418818730bc04e41f512e65331b3f206cb5eb9","upstream: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/dc7ab66ab23a054eaa942071cfb548d47fe4ca2f"]},"tags":{},"packages":[{"name":"gst-plugins-good1.0","source":"https://ubuntu.com/security/cve?package=gst-plugins-good1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gst-plugins-good1.0","debian":"https://tracker.debian.org/pkg/gst-plugins-good1.0","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.28.2-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.28.2-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.20.3-0ubuntu1.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.24.2-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.26.5-1ubuntu2.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-8317-1"],"notices":[{"id":"USN-8317-1","title":"GStreamer Good Plugins vulnerabilities","summary":"Several security issues were fixed in GStreamer Good Plugins.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-27T12:07:51.624281","description":"It was discovered that GStreamer Good Plugins incorrectly handled certain\nMP4 audio tracks. An attacker could possibly use this issue to cause\nGStreamer Good Plugins to crash, resulting in a denial of service.","is_hidden":false,"release_packages":{"jammy":[{"name":"gst-plugins-good1.0","version":"1.20.3-0ubuntu1.6","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.20.3-0ubuntu1.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.20.3-0ubuntu1.6","pocket":"security"}],"noble":[{"name":"gst-plugins-good1.0","version":"1.24.2-1ubuntu1.4","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"gstreamer1.0-qt6","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.24.2-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.24.2-1ubuntu1.4","pocket":"security"}],"questing":[{"name":"gst-plugins-good1.0","version":"1.26.5-1ubuntu2.3","description":"GStreamer plugins","is_source":true},{"name":"gstreamer1.0-gtk3","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"gstreamer1.0-plugins-good","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"gstreamer1.0-pulseaudio","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"gstreamer1.0-qt5","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"gstreamer1.0-qt6","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-0","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"},{"name":"libgstreamer-plugins-good1.0-dev","version":"1.26.5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0","version_link":"https://launchpad.net/ubuntu/+source/gst-plugins-good1.0/1.26.5-1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-46470","CVE-2026-46469"]}]},{"id":"CVE-2026-44544","published":"2026-05-14T18:16:00","updated_at":"2026-07-10T20:36:04.745946+00:00","description":"\ngittuf is a platform-agnostic Git security system. Prior to 0.14.0, an\nattacker with push access to gittuf's Reference State Log (RSL) can roll\nback the current policy to any previous policy trusted by the current set\nof root keys. gittuf determines the policy to load by inspecting the RSL.\nExcept for the very first policy (which is automatically trusted given\ngittuf's TOFU model, or verified against manually specified keys), whenever\nan RSL entry that points to a new policy is encountered, gittuf validates\nthat this policy is trusted. This is done by checking that the new policy’s\nroot metadata is signed by the required threshold of the current policy's\nroot keys. Because of this, an attacker with push access to the RSL may\ncreate a new entry that references an old policy (that is trusted by the\nmost recent policy's set of root keys), thereby rolling back gittuf's\npolicy to the attacker's chosen state. This vulnerability is fixed in\n0.14.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":4.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44544","https://github.com/gittuf/gittuf/security/advisories/GHSA-vxvc-cg7j-rwqj","https://github.com/gittuf/gittuf/commit/dd76efa505f9137a4a9a625c5ac67b333365a1b8"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136704"],"patches":{"gittuf":[]},"tags":{},"packages":[{"name":"gittuf","source":"https://ubuntu.com/security/cve?package=gittuf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gittuf","debian":"https://tracker.debian.org/pkg/gittuf","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44283","published":"2026-05-14T18:16:00","updated_at":"2026-05-22T17:53:24.785892+00:00","description":"\netcd is a distributed key-value store for the data of a distributed system.\nPrior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read\naccess via PrevKv, or lease attachment in Put requests within transaction\noperations, to bypass RBAC authorization checks. An authenticated user\nwithout sufficient read or lease-related permissions may be able to access\nunauthorized data or attach leases by invoking transaction operations with\nthese features enabled. This vulnerability is fixed in 3.4.44, 3.5.30, and\n3.6.11.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":0.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":0.0,"baseSeverity":"NONE"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44283","https://github.com/etcd-io/etcd/security/advisories/GHSA-x35m-3gp4-4fh5"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136829"],"patches":{"etcd":[]},"tags":{},"packages":[{"name":"etcd","source":"https://ubuntu.com/security/cve?package=etcd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=etcd","debian":"https://tracker.debian.org/pkg/etcd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41888","published":"2026-05-14T18:16:00","updated_at":"2026-07-10T20:12:56.638511+00:00","description":"\nDistribution is a toolkit to pack, ship, store, and deliver container\ncontent. Prior to 3.1.1, tag deletion via the DELETE\n/v2//manifests/ endpoint bypasses the storage.delete.enabled:\nfalse configuration, allowing any API client to remove tags from\nrepositories even when the operator has explicitly disabled deletion. This\nvulnerability is fixed in 3.1.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41888","https://github.com/distribution/distribution/security/advisories/GHSA-6pjf-3r9x-m592"],"bugs":[""],"patches":{"docker-registry":[]},"tags":{},"packages":[{"name":"docker-registry","source":"https://ubuntu.com/security/cve?package=docker-registry","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=docker-registry","debian":"https://tracker.debian.org/pkg/docker-registry","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45448","published":"2026-05-14T17:16:00","updated_at":"2026-05-21T11:53:28.910582+00:00","description":"\nCWE-601 URL redirection to untrusted site ('open redirect')","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45448","https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0"],"bugs":[""],"patches":{"ntopng":[]},"tags":{},"packages":[{"name":"ntopng","source":"https://ubuntu.com/security/cve?package=ntopng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntopng","debian":"https://tracker.debian.org/pkg/ntopng","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44348","published":"2026-05-14T17:16:00","updated_at":"2026-05-22T17:55:22.774069+00:00","description":"\nPoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a\ndouble-free vulnerability exists in compute_hash_to_sign() in\nsrc/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFinal fails\nafter buf has already been freed, the Error label frees buf a second time,\ncausing heap corruption. This vulnerability is fixed in 1.0.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":2.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44348","https://github.com/podofo/podofo/security/advisories/GHSA-8fq6-rqpv-xq72","https://github.com/podofo/podofo/commit/696d765c3a71ef224d4abffe1f174fef11292d7e"],"bugs":[""],"patches":{"libpodofo":[]},"tags":{},"packages":[{"name":"libpodofo","source":"https://ubuntu.com/security/cve?package=libpodofo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpodofo","debian":"https://tracker.debian.org/pkg/libpodofo","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44312","published":"2026-05-14T17:16:00","updated_at":"2026-05-21T12:00:18.416989+00:00","description":"\ncss_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser\ngem does not validate HTTPS connections, allowing a Man-in-the-Middle\n(MITM) attacker to inject or modify CSS content when stylesheets are loaded\nvia HTTPS. The connection is established with OpenSSL::SSL::VERIFY_NONE,\nmeaning any HTTPS certificate—even entirely untrusted—will be accepted\nwithout validation. This vulnerability is fixed in 2.1.0 and 1.22.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44312","https://github.com/premailer/css_parser/security/advisories/GHSA-ff6c-w6qf-7xqc","https://github.com/premailer/css_parser/issues/185","https://github.com/premailer/css_parser/commit/35e689c904225add78e0c488cf04bad052666449","https://github.com/premailer/css_parser/commit/e0c95d5abe91b237becb90ff316531a6547ada18"],"bugs":[""],"patches":{"ruby-css-parser":[]},"tags":{},"packages":[{"name":"ruby-css-parser","source":"https://ubuntu.com/security/cve?package=ruby-css-parser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-css-parser","debian":"https://tracker.debian.org/pkg/ruby-css-parser","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44216","published":"2026-05-14T15:16:00","updated_at":"2026-06-30T18:47:46.282315+00:00","description":"\nWasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and\n44.0.1, Wasmtime's allocation logic for a WebAssembly table contained\nchecked arithmetic which panicked on overflow. This overflow is possible to\ntrigger, and thus panic, when a table with an extremely large size is\nallocated. This is possible with the WebAssembly memory64 proposal where\ntables can have sizes in the 64-bit range as opposed to the previous 32-bit\nrange which would not overflow. The panic happens when attempting to create\na very large table, such as when instantiating a WebAssembly module or\ncomponent. This vulnerability is fixed in 36.0.8, 43.0.2, and 44.0.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44216","https://github.com/bytecodealliance/wasmtime/security/advisories/GHSA-p8xm-42r7-89xg"],"bugs":[""],"patches":{"rust-wasmtime":[]},"tags":{},"packages":[{"name":"rust-wasmtime","source":"https://ubuntu.com/security/cve?package=rust-wasmtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-wasmtime","debian":"https://tracker.debian.org/pkg/rust-wasmtime","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"36.0.8+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-24712","published":"2026-05-14T15:16:00","updated_at":"2026-06-18T18:43:46.616545+00:00","description":"\nNorthern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and\n3.27.0 allows Command injection.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-24712","https://cfengine.com/blog/2026/cve-2026-24710-and-cve-2026-24711-and-cve-2026-24712/"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139174"],"patches":{"cfengine3":[]},"tags":{},"packages":[{"name":"cfengine3","source":"https://ubuntu.com/security/cve?package=cfengine3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cfengine3","debian":"https://tracker.debian.org/pkg/cfengine3","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6638","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:08:49.250173+00:00","description":"\nSQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ...\nREFRESH PUBLICATION allows a subscriber table creator to execute arbitrary\nSQL with the subscription's publication-side credentials. The attack takes\neffect at the next REFRESH PUBLICATION. Within major versions 16, 17, and\n18, minor versions before PostgreSQL 18.4, 17.10, and 16.14 are affected.\nVersions before PostgreSQL 16 are unaffected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6638","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6638/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]},{"id":"CVE-2026-6637","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:08:06.998027+00:00","description":"\nStack buffer overflow in PostgreSQL module \"refint\" allows an unprivileged\ndatabase user to execute arbitrary code as the operating system user\nrunning the database. A distinct attack is possible if the application\ndeclares a user-controlled column as a \"refint\" cascade primary key and\nfacilitates user-controlled updates to that column. In that case, a SQL\ninjection allows a primary key update value provider to execute arbitrary\nSQL as the database user performing the primary key update. Versions\nbefore PostgreSQL 18.4, 17.10, 16.14, 15.18, and 14.23 are affected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6637","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6637/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]},{"id":"CVE-2026-6575","published":"2026-05-14T14:16:00","updated_at":"2026-05-22T18:07:47.423203+00:00","description":"\nBuffer over-read in PostgreSQL function pg_restore_attribute_stats()\naccepts array values of unmatched length, which causes query planning to\nread past end of one array. This allows a table maintainer to infer memory\nvalues past that array end. Within major version 18, minor versions before\nPostgreSQL 18.4 are affected. Versions before PostgreSQL 18 are\nunaffected.","ubuntu_description":"","notes":[{"author":"leosilva","note":"PostgreSQL 9.3 is end of life upstream, and no updates are\nare available. Marking as deferred in -esm-main releases."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6575","https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/","https://www.postgresql.org/support/security/CVE-2026-6575/","https://ubuntu.com/security/notices/USN-8294-1"],"bugs":[""],"patches":{"postgresql-18":[],"postgresql-17":[],"postgresql-16":[],"postgresql-14":[],"postgresql-12":[],"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-14","source":"https://ubuntu.com/security/cve?package=postgresql-14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-14","debian":"https://tracker.debian.org/pkg/postgresql-14","statuses":[{"release_codename":"jammy","status":"released","description":"14.23-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-16","source":"https://ubuntu.com/security/cve?package=postgresql-16","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-16","debian":"https://tracker.debian.org/pkg/postgresql-16","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"16.14-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-17","source":"https://ubuntu.com/security/cve?package=postgresql-17","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-17","debian":"https://tracker.debian.org/pkg/postgresql-17","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"17.10-0ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-18","source":"https://ubuntu.com/security/cve?package=postgresql-18","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-18","debian":"https://tracker.debian.org/pkg/postgresql-18","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"18.4-0ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"trusty","status":"deferred","description":"2019-08-23","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-8294-1"],"notices":[{"id":"USN-8294-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.","references":[],"published":"2026-05-21T20:39:48.706022","description":"It was discovered that PostgreSQL did not correctly enforce authorization\nfor CREATE TYPE. An attacker could possibly use this issue to execute\narbitrary SQL functions. (CVE-2026-6472)\n\nIt was discovered that PostgreSQL incorrectly handled large user input in\nmultiple server features. An attacker could possibly use this issue to\ncause PostgreSQL to crash, resulting in a denial of service, or execute\narbitrary code. (CVE-2026-6473)\n\nIt was discovered that PostgreSQL incorrectly handled format strings in\nthe timeofday() function. An attacker could possibly use this issue to\nobtain sensitive information. (CVE-2026-6474)\n\nIt was discovered that PostgreSQL incorrectly followed symbolic links in\npg_basebackup and pg_rewind. An attacker could possibly use this issue to\noverwrite local files and execute arbitrary code. (CVE-2026-6475)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\npg_createsubscriber. An attacker could possibly use this issue to execute\narbitrary SQL as a superuser. This issue only affected Ubuntu 25.10 and\nUbuntu 26.04 LTS. (CVE-2026-6476)\n\nIt was discovered that PostgreSQL used an unsafe libpq function in large\nobject operations. An attacker could possibly use this issue to overwrite\nclient memory and execute arbitrary code. (CVE-2026-6477)\n\nIt was discovered that PostgreSQL did not compare MD5-hashed passwords in\nconstant time. An attacker could possibly use this issue to obtain\nsensitive information. (CVE-2026-6478)\n\nIt was discovered that PostgreSQL had uncontrolled recursion during SSL and\nGSS negotiation. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2026-6479)\n\nIt was discovered that PostgreSQL incorrectly handled array length\nmismatches in pg_restore_attribute_stats(). An attacker could possibly use\nthis issue to obtain sensitive information. This issue only affected Ubuntu\n26.04 LTS. (CVE-2026-6575)\n\nIt was discovered that PostgreSQL had a stack buffer overflow in the refint\nmodule. An attacker could use this issue to cause PostgreSQL to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2026-6637)\n\nIt was discovered that PostgreSQL had an SQL injection vulnerability in\nlogical replication REFRESH PUBLICATION. An attacker could possibly use\nthis issue to execute arbitrary SQL. This issue only affected Ubuntu 24.04\nLTS, Ubuntu 25.10, and Ubuntu 26.04 LTS. (CVE-2026-6638)","is_hidden":false,"release_packages":{"jammy":[{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libecpg6","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpgtypes3","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq-dev","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"libpq5","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-client-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-doc-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plperl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-plpython3-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-pltcl-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"},{"name":"postgresql-server-dev-14","version":"14.23-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-14","version_link":"https://launchpad.net/ubuntu/+source/postgresql-14/14.23-0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libecpg6","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpgtypes3","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq-dev","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"libpq5","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-client-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-doc-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plperl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-plpython3-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-pltcl-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"},{"name":"postgresql-server-dev-16","version":"16.14-0ubuntu0.24.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-16","version_link":"https://launchpad.net/ubuntu/+source/postgresql-16/16.14-0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libecpg6","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpgtypes3","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq-dev","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"libpq5","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-client-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-doc-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plperl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-plpython3-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-pltcl-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"},{"name":"postgresql-server-dev-17","version":"17.10-0ubuntu0.25.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-17","version_link":"https://launchpad.net/ubuntu/+source/postgresql-17/17.10-0ubuntu0.25.10.1","pocket":"security"}],"resolute":[{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libecpg6","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpgtypes3","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-dev","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq-oauth","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"libpq5","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-18-jit","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-client-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-doc-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plperl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-plpython3-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-pltcl-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"},{"name":"postgresql-server-dev-18","version":"18.4-0ubuntu0.26.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-18","version_link":"https://launchpad.net/ubuntu/+source/postgresql-18/18.4-0ubuntu0.26.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-6475","CVE-2026-6637","CVE-2026-6575","CVE-2026-6478","CVE-2026-6473","CVE-2026-6477","CVE-2026-6638","CVE-2026-6472","CVE-2026-6476","CVE-2026-6474","CVE-2026-6479"]}]}],"offset":11620,"limit":20,"total_results":79316}