{"cves":[{"id":"CVE-2026-88044","published":"2026-09-10T17:17:00","updated_at":"2026-09-16T22:47:15.031128+00:00","description":"\nrclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. From 1.70.0 until 1.75.1, the\nserve/start RC interface accepts per-server proxyOpt.AuthProxy settings,\nand the FTP and S3 constructors in cmd/serve/ftp/ftp.go and\ncmd/serve/s3/server.go incorrectly check the process-global\nproxy.Opt.AuthProxy value instead. When the global value is empty, the\nrequest-local authentication proxy is ignored: FTP falls back to the fixed\nfilesystem with username anonymous and any password, while S3 with AuthKey\nserves the fixed RC fs rather than the backend selected by the proxy. The\ndedicated command-line servers that configure the global option are not\naffected. This issue is fixed in version 1.75.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88044"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88018","published":"2026-09-10T16:18:00","updated_at":"2026-09-16T22:52:31.048127+00:00","description":"\nrclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. Prior to 1.75.1, rclone serve s3\nconfigured with --auth-proxy but without --auth-key allows\nauthPairMiddleware to register any client-chosen accessKeyID with an empty\nws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against\nthat same empty secret, while Server.auth passes the access key identifier\nas both the user and authentication value to the proxy without an\nindependent per-identity secret. An unauthenticated network attacker can\ntherefore choose an arbitrary access key, sign with an empty secret, and\nreach whatever backend the auth-proxy script resolves for that identity.\nThis issue is fixed in version 1.75.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88018","https://github.com/rclone/rclone/security/advisories/GHSA-xwwr-4h3p-r22c"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88017","published":"2026-09-10T16:18:00","updated_at":"2026-09-16T22:35:19.022582+00:00","description":"\nrclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. From 1.64.0 until 1.75.1, the FTP\nauth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per\nusername in the server-wide userPass map[string]string instead of binding\nthe credential or VFS to the authenticated session. If two accepted\ncredentials use the same username but resolve to different proxy backends,\na later CheckPasswd login overwrites userPass[user], and subsequent getVFS\noperations on the first session are reauthorized with the later password.\nThe first session can then read, create, overwrite, rename, or delete\nobjects using the second credential’s backend authority. Exploitation\nrequires the later same-username login to occur while the first session\nremains open. This issue is fixed in version 1.75.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88017","https://github.com/rclone/rclone/security/advisories/GHSA-c476-6w5q-jw77"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88016","published":"2026-09-10T16:18:00","updated_at":"2026-09-16T22:47:15.031128+00:00","description":"\nrclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. Prior to 1.75.1, when backend/local runs\nwith --links, a source .rclonelink object can plant a symlink in the\ndestination and later directory metadata is applied through that path.\nMkdirMetadata, writeMetadataToFile, and setTimes operate when\nDirectory.translatedLink=false, so os.Chown, os.Chmod, os.Chtimes, and\nbirth-time handling can bypass os.Root confinement and follow the symlink.\nAn attacker controlling source contents can therefore apply selected\nownership, permissions, modification times, or birth times to a file or\ndirectory outside the destination, with --metadata required for chmod and\nchown while modification time is applied by the normal directory workflow.\nThis issue is fixed in version 1.75.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88016","https://github.com/rclone/rclone/security/advisories/GHSA-f8g7-2xjc-7mfh"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88015","published":"2026-09-10T16:18:00","updated_at":"2026-09-16T19:29:33.870678+00:00","description":"\nrclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. Prior to 1.75.1, backend/local with\n--links or links=true exposes symlink targets as .rclonelink objects, and\nfs.RangeOption.Decode can pass an unchecked positive Range start through\nObject.Open and openTranslatedLink. The function slices the target string\nas linkdst[offset:], so a Range start larger than the target length causes\na deterministic slice-bounds panic when lib/http/serve exposes the object\nthrough HTTP or WebDAV. Go net/http normally recovers the panic per\nconnection, causing request-level denial of service rather than terminating\nthe entire process. This issue is fixed in version 1.75.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88015","https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88014","published":"2026-09-10T16:18:00","updated_at":"2026-09-16T22:47:15.031128+00:00","description":"\nrclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. From 1.72.0 until 1.75.1, the archive\nZIP backend method (*Fs).readZip in backend/archive/zip/zip.go accepts\narchive/zip.File.Name values from an untrusted central directory and\nexposes cleaned entry names without ensuring that they remain inside the\narchive namespace. Entries such as ../../etc/cron.d/evil can survive\npath.Clean and become Object.Remote() values that fs/sync and fs/operations\nuse as destination-relative paths, allowing rclone copy or sync to write\noutside the selected destination on backends that do not independently\nconfine the path. The non-empty root check also used strings.HasPrefix\nwithout a path boundary, so root foo could incorrectly include sibling\nfoobar entries. This issue is fixed in version 1.75.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88014","https://github.com/rclone/rclone/security/advisories/GHSA-66hp-wgxq-6f5q"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88013","published":"2026-09-10T16:18:00","updated_at":"2026-09-16T21:02:35.982428+00:00","description":"\nrclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. From 1.49.0 until 1.75.1, the HTTP\nbackend attaches headers configured through --http-headers or headers= to\nrequests in backend/http/http.go, while its fshttp.NewClient client follows\nredirects without a backend-specific http.Client.CheckRedirect policy. A\nconfigured remote that redirects to another host can therefore cause custom\nsecrets such as X-Api-Key to be resent to that untrusted destination, and a\nsame-host HTTPS-to-HTTP redirect can expose Authorization or Cookie headers\nin cleartext. Listing, stat, download, mount, and serve operations can\ntrigger the leak during normal use. This issue is fixed in version 1.75.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88013","https://github.com/rclone/rclone/security/advisories/GHSA-486v-q2wf-fp2r"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88924","published":"2026-09-10T15:17:00","updated_at":"2026-09-16T22:37:25.128798+00:00","description":"\nA flaw was found in the admin backend of gvfs. The privileged gvfsd-admin\ndaemon changes the ownership of newly created private D-Bus sockets by\ncalling the link-following chown() function on a pathname inside a\nuser-controlled directory. A local attacker can exploit this via a\nTime-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket\npathname with a symbolic link pointing to an arbitrary root-owned file\n(such as /etc/pam.d/su). The daemon subsequently follows the symlink and\nchanges the ownership of the targeted root-owned file to the attacker's\nuser ID. This allows an authenticated local attacker to modify critical\nsystem files, leading to a full local privilege escalation to root.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88924","https://gitlab.gnome.org/GNOME/gvfs/-/issues/875","https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/352"],"bugs":[""],"patches":{"gvfs":[]},"tags":{},"packages":[{"name":"gvfs","source":"https://ubuntu.com/security/cve?package=gvfs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gvfs","debian":"https://tracker.debian.org/pkg/gvfs","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-46387","published":"2026-09-10T15:17:00","updated_at":"2026-09-16T10:39:57.993148+00:00","description":"\nSuricata is a network Intrusion Detection System, Intrusion Prevention\nSystem and Network Security Monitoring engine. Prior to versions 7.0.16 and\n8.0.5, Suricata's HTTP/2 decompression path could grow the decompressed\nresponse-body buffer without an effective upper bound. A crafted HTTP/2\nDATA payload using a high compression ratio, such as gzip, deflate, or\nbrotli compressed data, could cause Suricata to allocate excessive memory\nwhile decompressing the payload. Versions 7.0.16 and 8.0.5 contain a fix.\nAs a workaround, disable HTTP2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46387"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45747","published":"2026-09-10T15:17:00","updated_at":"2026-09-16T10:38:23.322119+00:00","description":"\nSuricata is a network Intrusion Detection System, Intrusion Prevention\nSystem and Network Security Monitoring engine. Prior to version 7.0.16, the\nLua TLS certificate information helper could dereference NULL certificate\nfields when a Lua script requested certificate information for TLS traffic\nwhere some certificate fields were absent. Crafted TLS traffic processed by\na deployment using affected Lua TLS scripting could crash Suricata,\nresulting in denial of service. Version 7.0.16 contains a fix. As a\nworkaround, avoid Lua scripts that call TLS certificate information helpers\non untrusted traffic (`TlsGetCertInfo` function), or update scripts to\nhandle missing certificate fields where possible.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45747"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-45763","published":"2026-09-10T14:17:00","updated_at":"2026-09-16T10:38:23.322119+00:00","description":"\nSuricata is a network Intrusion Detection System, Intrusion Prevention\nSystem and Network Security Monitoring engine. Starting in version 8.0.0\nand prior to version 8.0.5, when Lua rule execution is enabled, the Lua\nsandbox memory limit was not consistently enforced for new allocations.\nCertain Lua allocation patterns could exceed `security.lua.max-bytes`\nwithout triggering the intended memory limit, making the configured sandbox\nlimit unreliable. This requires Lua rules to be enabled and an affected Lua\nscript/rule to be loaded. Version 8.0.5 contains a fix. As a workaround,\ndisable `security.lua.allow-rules` unless Lua rules are required.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-45763"],"bugs":[""],"patches":{"suricata":[]},"tags":{},"packages":[{"name":"suricata","source":"https://ubuntu.com/security/cve?package=suricata","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=suricata","debian":"https://tracker.debian.org/pkg/suricata","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88038","published":"2026-09-10T13:20:00","updated_at":"2026-09-16T18:52:32.574299+00:00","description":"\ncookies is a Node.js library for reading and writing HTTP cookies, used by\nKoa via ctx.cookies. In versions before 0.9.2 the library validates the\ncookie name and value against character sets that reject the semicolon\nseparator, but the domain and path options are checked only against a\npermissive RFC 7230 field-content matcher that allows semicolons, and both\nare written into the Set-Cookie header unescaped. An application that\npasses untrusted or request-derived data into the domain or path option can\ntherefore inject additional cookie attributes, overriding SameSite, Secure,\nHttpOnly, or Domain on the cookies the application issues. This is a\nSet-Cookie attribute injection issue (CWE-74). The issue is fixed in\ncookies 0.9.2, which validates domain and path against RFC 6265 character\nsets. As a workaround, keep domain and path application-set rather than\nderived from untrusted input.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88038","https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf","https://cna.openjsf.org/security-advisories.html"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147405"],"patches":{"node-cookies":[]},"tags":{},"packages":[{"name":"node-cookies","source":"https://ubuntu.com/security/cve?package=node-cookies","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-cookies","debian":"https://tracker.debian.org/pkg/node-cookies","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.2+~0.9.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88859","published":"2026-09-10T12:16:00","updated_at":"2026-09-16T17:08:41.763825+00:00","description":"\nA flaw was found in Evolution. A remote attacker can exploit this\nvulnerability by sending a specially crafted HTML email containing a\nspoofed vCard control. When a victim clicks on this control, Evolution's\ntrusted JavaScript handler incorrectly assigns an attacker-controlled\nJavaScript URL to an iframe's source. This action leads to arbitrary\nJavaScript execution within the mail-viewing context, effectively bypassing\nthe security measures designed to prevent script execution in email\ncontent.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88859","https://gitlab.gnome.org/GNOME/evolution/-/work_items/3388"],"bugs":[""],"patches":{"evolution":[]},"tags":{},"packages":[{"name":"evolution","source":"https://ubuntu.com/security/cve?package=evolution","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=evolution","debian":"https://tracker.debian.org/pkg/evolution","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-84828","published":"2026-09-10T12:16:00","updated_at":"2026-09-16T16:44:14.762546+00:00","description":"\nA flaw was found in PCS (Pacemaker Configuration System). A local attacker\nwith membership in the 'haclient' group can exploit the 'pcs host auth\n--token' command to read the contents of arbitrary files on the filesystem,\nprovided the files are shorter than 256 bytes. The file contents are read\nwith root privileges by the pcsd daemon and can be exfiltrated by the\nattacker through subsequent cluster node communication. This allows\ndisclosure of sensitive data such as API keys, tokens, or configuration\nsecrets that would otherwise be inaccessible to the attacker.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"per Red Hat bug, introduced in 0.10.8 with:\nhttps://github.com/ClusterLabs/pcs/commit/9178b78d11baa70e700a5c0d9fc1c17f27d452fa\n\nThe commit that fixes this issue is not public yet as of\n2026-09-11, marking as deferred for now."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-84828"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=2527320"],"patches":{"pcs":["upstream: https://github.com/ClusterLabs/pcs/commit/b41eaf3c6e2ecfc575c42442fb02b8ef05b4dd6a"]},"tags":{},"packages":[{"name":"pcs","source":"https://ubuntu.com/security/cve?package=pcs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcs","debian":"https://tracker.debian.org/pkg/pcs","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"see notes","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2026-09-11","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2026-09-11","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2026-09-11","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"see notes","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-87962","published":"2026-09-10T11:17:00","updated_at":"2026-09-16T18:46:28.788385+00:00","description":"\nt-digest versions 3.1 through 3.3 contain a denial of service vulnerability\nin MergingDigest.fromBytes that fails to validate length and capacity\nfields from serialized data. Attackers can supply crafted serialized\ndigests with mismatched header fields to trigger\nArrayIndexOutOfBoundsException or NegativeArraySizeException, aborting the\nparsing thread.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-87962"],"bugs":[""],"patches":{"t-digest":[]},"tags":{},"packages":[{"name":"t-digest","source":"https://ubuntu.com/security/cve?package=t-digest","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=t-digest","debian":"https://tracker.debian.org/pkg/t-digest","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88265","published":"2026-09-10T09:17:00","updated_at":"2026-09-16T22:22:15.260209+00:00","description":"\nA flaw was found in crun. After pivot_root, reopening /dev/null for stdio\ncan follow a symlink and attach a host file to container stdio, then change\nthat file's ownership. Affected versions are crun 1.29.1 and earlier.\nDefault configurations that mount a fresh /dev are not exposed. No fixed\nrelease is available yet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88265"],"bugs":[""],"patches":{"crun":[]},"tags":{},"packages":[{"name":"crun","source":"https://ubuntu.com/security/cve?package=crun","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=crun","debian":"https://tracker.debian.org/pkg/crun","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-88264","published":"2026-09-10T09:17:00","updated_at":"2026-09-16T18:52:32.574299+00:00","description":"\nA flaw was found in crun. When the container configuration does not give\n/dev a dedicated mount, terminal setup can redirect /dev/console onto an\nattacker-controlled path, including via the read-only-rootfs bind-mount\nfallback. Affected versions are crun 1.29.1 and earlier. Default\nconfigurations that mount a fresh /dev are not exposed. No fixed release is\navailable yet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-88264"],"bugs":[""],"patches":{"crun":[]},"tags":{},"packages":[{"name":"crun","source":"https://ubuntu.com/security/cve?package=crun","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=crun","debian":"https://tracker.debian.org/pkg/crun","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-84042","published":"2026-09-10T09:17:00","updated_at":"2026-09-16T11:10:22.623351+00:00","description":"\nA flaw was found in crun. When crun is built with libkrun and a container\nis started rootful with passt networking (krun.use_passt), crun can execute\nattacker-controlled payload from the container image with host root\nprivileges. The issue is a regression in crun 1.29. It affects crun >= 1.29","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-84042"],"bugs":[""],"patches":{"crun":[]},"tags":{},"packages":[{"name":"crun","source":"https://ubuntu.com/security/cve?package=crun","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=crun","debian":"https://tracker.debian.org/pkg/crun","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59679","published":"2026-09-10T09:17:00","updated_at":"2026-09-16T10:43:23.509575+00:00","description":"\nfs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c)\nindexes the per-character encoding[] array using num_chars from the\nFS_QueryXBitmaps16 reply, but that array was allocated with a size derived\nfrom num_extents in the separate FS_QueryXExtents16 reply. The two CARD32\nfields are never cross-checked.\nA malicious or compromised font server can send a small num_extents (e.g.\n1) in the extents reply, then a large num_chars (e.g. 100000) in the\nbitmaps reply. This causes attacker-controlled out-of-bounds heap read and\nwrites.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.0,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":9.2,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59679","https://www.openwall.com/lists/oss-security/2026/08/05/1"],"bugs":[""],"patches":{"libxfont":[],"libxfont2":[]},"tags":{},"packages":[{"name":"libxfont","source":"https://ubuntu.com/security/cve?package=libxfont","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxfont","debian":"https://tracker.debian.org/pkg/libxfont","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libxfont2","source":"https://ubuntu.com/security/cve?package=libxfont2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxfont2","debian":"https://tracker.debian.org/pkg/libxfont2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44950","published":"2026-09-10T09:17:00","updated_at":"2026-09-16T10:35:02.555237+00:00","description":"\nfs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c)\ncopies each glyph's bitmap into a single buffer. Existing checks validates\nonly that the source slice (position, length) lies within the source bitmap\nbuffer. It does not check whether the running destination cursor has\nexceeded the allocation.\nA malicious font server can send overlapping source offsets -- for example\n1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each\nindividual source range passes the existing validation, but the cumulative\nwrites total 64000 bytes into a 64-byte destination buffer. This is a heap\nbuffer overflow with attacker-controlled content.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.0,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},"baseScore":9.5,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44950","https://www.openwall.com/lists/oss-security/2026/08/05/1"],"bugs":[""],"patches":{"libxfont":[],"libxfont2":[]},"tags":{},"packages":[{"name":"libxfont","source":"https://ubuntu.com/security/cve?package=libxfont","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxfont","debian":"https://tracker.debian.org/pkg/libxfont","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libxfont2","source":"https://ubuntu.com/security/cve?package=libxfont2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxfont2","debian":"https://tracker.debian.org/pkg/libxfont2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":1380,"limit":20,"total_results":79316}