{"cves":[{"id":"CVE-2025-70873","published":"2026-03-12T19:16:00","updated_at":"2026-03-18T12:17:19.588923+00:00","description":"\nAn information disclosure issue in the zipfileInflate function in the\nzipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain\nheap memory via supplying a crafted ZIP file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"The Ubuntu sqlite3 packages does not build the vulnerable\nsqlite/ext/misc/zipfile.c file."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-70873","https://gist.github.com/cnwangjihe/f496393f30f5ecec5b18c8f5ab072054"],"bugs":[""],"patches":{"sqlite":[],"sqlite3":[]},"tags":{},"packages":[{"name":"sqlite","source":"https://ubuntu.com/security/cve?package=sqlite","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sqlite","debian":"https://tracker.debian.org/pkg/sqlite","statuses":[{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]},{"name":"sqlite3","source":"https://ubuntu.com/security/cve?package=sqlite3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sqlite3","debian":"https://tracker.debian.org/pkg/sqlite3","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not compiled","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-32141","published":"2026-03-12T18:16:00","updated_at":"2026-03-18T12:17:04.104872+00:00","description":"\nflatted is a circular JSON parser. Prior to 3.4.0, flatted's parse()\nfunction uses a recursive revive() phase to resolve circular references in\ndeserialized JSON. When given a crafted payload with deeply nested or\nself-referential $ indices, the recursion depth is unbounded, causing a\nstack overflow that crashes the Node.js process. This vulnerability is\nfixed in 3.4.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-32141"],"bugs":[""],"patches":{"node-flatted":[]},"tags":{},"packages":[{"name":"node-flatted","source":"https://ubuntu.com/security/cve?package=node-flatted","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-flatted","debian":"https://tracker.debian.org/pkg/node-flatted","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-32116","published":"2026-03-12T18:16:00","updated_at":"2026-07-10T20:03:10.608710+00:00","description":"\nMagic Wormhole makes it possible to get arbitrary-sized files and\ndirectories from one computer to another. From 0.21.0 to before 0.23.0,\nreceiving a file (wormhole receive) from a malicious party could result in\noverwriting critical local files, including ~/.ssh/authorized_keys and\n.bashrc. This could be used to compromise the receiver's computer. Only the\nsender of the file (the party who runs wormhole send) can mount the attack.\nOther parties (including the transit/relay servers) are excluded by the\nwormhole protocol. This vulnerability is fixed in 0.23.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-32116"],"bugs":[""],"patches":{"magic-wormhole":[]},"tags":{},"packages":[{"name":"magic-wormhole","source":"https://ubuntu.com/security/cve?package=magic-wormhole","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=magic-wormhole","debian":"https://tracker.debian.org/pkg/magic-wormhole","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-13462","published":"2026-03-12T18:16:00","updated_at":"2026-07-06T13:33:28.720348+00:00","description":"\nThe \"tarfile\" module would still apply normalization of AREGTYPE (\\x00)\nblocks to DIRTYPE, even while processing a multi-block member such as\nGNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar\narchive being misinterpreted by the tarfile module compared to other\nimplementations.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.0,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-13462","https://ubuntu.com/security/notices/USN-8509-1"],"bugs":["https://github.com/python/cpython/issues/141707"],"patches":{"python2.7":[],"python3.4":[],"python3.5":[],"python3.6":[],"python3.7":[],"python3.8":[],"python3.9":[],"python3.10":[],"python3.11":["upstream: https://github.com/python/cpython/commit/9a23b753552afa28e3a2f4d8863572fc66479406"],"python3.12":["upstream: https://github.com/python/cpython/commit/d10950739a78f54d0718d88fb5a868374603c084"],"python3.13":["upstream: https://github.com/python/cpython/commit/ae99fe3a33b43e303a05f012815cef60b611a9c7"],"python3.14":[]},"tags":{},"packages":[{"name":"python3.10","source":"https://ubuntu.com/security/cve?package=python3.10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.10","debian":"https://tracker.debian.org/pkg/python3.10","statuses":[{"release_codename":"jammy","status":"released","description":"3.10.12-1~22.04.16","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.12","source":"https://ubuntu.com/security/cve?package=python3.12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.12","debian":"https://tracker.debian.org/pkg/python3.12","statuses":[{"release_codename":"noble","status":"released","description":"3.12.3-1ubuntu0.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"}]},{"name":"python3.13","source":"https://ubuntu.com/security/cve?package=python3.13","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.13","debian":"https://tracker.debian.org/pkg/python3.13","statuses":[{"release_codename":"upstream","status":"released","description":"3.13.14-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python3.14","source":"https://ubuntu.com/security/cve?package=python3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.14","debian":"https://tracker.debian.org/pkg/python3.14","statuses":[{"release_codename":"resolute","status":"not-affected","description":"3.14.4-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.14.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"python2.7","source":"https://ubuntu.com/security/cve?package=python2.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.7","debian":"https://tracker.debian.org/pkg/python2.7","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.11","source":"https://ubuntu.com/security/cve?package=python3.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.11","debian":"https://tracker.debian.org/pkg/python3.11","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.4","source":"https://ubuntu.com/security/cve?package=python3.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.4","debian":"https://tracker.debian.org/pkg/python3.4","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.5","source":"https://ubuntu.com/security/cve?package=python3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.5","debian":"https://tracker.debian.org/pkg/python3.5","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.6","source":"https://ubuntu.com/security/cve?package=python3.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.6","debian":"https://tracker.debian.org/pkg/python3.6","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.7","source":"https://ubuntu.com/security/cve?package=python3.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.7","debian":"https://tracker.debian.org/pkg/python3.7","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.8","source":"https://ubuntu.com/security/cve?package=python3.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.8","debian":"https://tracker.debian.org/pkg/python3.8","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.9","source":"https://ubuntu.com/security/cve?package=python3.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.9","debian":"https://tracker.debian.org/pkg/python3.9","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8509-1"],"notices":[{"id":"USN-8509-1","title":"Python vulnerabilities","summary":"Several security issues were fixed in Python.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-06T11:48:55.248878","description":"It was discovered that Python incorrectly normalized paths in the tarfile\nmodule. An attacker could possibly use this issue to bypass path\nrestrictions. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04\nLTS. (CVE-2025-13462)\n\nIt was discovered that Python's HTMLParser incorrectly handled certain\nmalformed HTML input. An attacker could possibly use this issue to cause\nPython to crash, resulting in a denial of service. This issue only affected\nUbuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2025-69534)\n\nIt was discovered that Python's email module incorrectly quoted newlines\nin headers. An attacker could possibly use this issue to inject arbitrary\nemail headers. This issue only affected Ubuntu 22.04 LTS and Ubuntu\n24.04 LTS. (CVE-2026-1299)\n\nIt was discovered that Python's http.client module did not properly\nsanitize carriage return and linefeed characters when handling HTTP\nCONNECT tunnel request headers. An attacker could possibly use this issue\nto inject arbitrary HTTP headers. (CVE-2026-1502)\n\nIt was discovered that Python's importlib module did not generate an\naudit event when loading legacy .pyc files. An attacker could possibly\nuse this issue to bypass auditing mechanisms. This issue only affected\nUbuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-2297)\n\nIt was discovered that Python's unicodedata.normalize() function had\nincorrect algorithmic complexity. An attacker could possibly use this\nissue to cause Python to consume excessive resources, leading to a denial\nof service. (CVE-2026-3276)\n\nIt was discovered that Python's http.cookies module incorrectly handled\ncontrol characters in certain cookie operations. An attacker could possibly\nuse this issue to inject arbitrary content. This issue only affected Ubuntu\n22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-3644)\n\nIt was discovered that the Python pyexpat module was vulnerable to\nunbounded recursion in the Expat XML parser. An attacker could possibly use\nthis issue to cause Python to crash, resulting in a denial of service. This\nissue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-4224)\n\nIt was discovered that Python's webbrowser module accepted leading dashes\nin URLs, which could be interpreted as command-line options. An attacker\ncould possibly use this issue to execute arbitrary commands. This issue\nonly affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-4519)\n\nIt was discovered that Python incorrectly handled webbrowser.open()\nhandlers. An attacker could possibly use this issue to execute arbitrary\ncommands. (CVE-2026-4786)\n\nIt was discovered that Python's remote debugging module did not properly\nvalidate offset tables when loading debug information. An attacker could\npossibly use this issue to cause Python to crash or execute arbitrary\ncode. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-5713)\n\nIt was discovered that Python's http.cookies module incorrectly escaped\nvalues in the js_output() method. An attacker could possibly use this issue\nto inject arbitrary JavaScript. (CVE-2026-6019)\n\nIt was discovered that Python's lzma, bz2, and gzip decompressor objects\nhad a use-after-free vulnerability. An attacker could possibly use this\nissue to cause Python to crash or execute arbitrary code. (CVE-2026-6100)\n\nIt was discovered that Python's tarfile module did not properly validate\nlink targets when using the data filter. An attacker could possibly use\nthis issue to bypass path restrictions. This issue only affected Ubuntu\n24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-7774)\n\nIt was discovered that the fix for CVE-2021-4189 in Python's ftplib module\nwas incomplete, allowing PASV responses to be used in ftplib.ftpcp(). An\nattacker could possibly use this issue to perform server-side request\nforgery attacks. (CVE-2026-8328)\n\nIt was discovered that Python's bz2 module allowed reuse of a\nBZ2Decompressor object after a decompression error. An attacker could\npossibly use this issue to cause Python to crash or execute arbitrary\ncode. (CVE-2026-9669)","is_hidden":false,"release_packages":{"jammy":[{"name":"python3.10","version":"3.10.12-1~22.04.16","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.10","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"libpython3.10","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"libpython3.10-dev","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"libpython3.10-minimal","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"libpython3.10-stdlib","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"libpython3.10-testsuite","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"python3.10","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"python3.10-dev","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"python3.10-doc","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"python3.10-examples","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"python3.10-full","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"python3.10-minimal","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"python3.10-nopie","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"},{"name":"python3.10-venv","version":"3.10.12-1~22.04.16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.10","version_link":"https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.16","pocket":"security"}],"noble":[{"name":"python3.12","version":"3.12.3-1ubuntu0.15","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.12","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"libpython3.12-dev","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"libpython3.12-minimal","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"libpython3.12-stdlib","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"libpython3.12-testsuite","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"libpython3.12t64","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"python3.12","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"python3.12-dev","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"python3.12-doc","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"python3.12-examples","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"python3.12-full","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"python3.12-minimal","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"python3.12-nopie","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"},{"name":"python3.12-venv","version":"3.12.3-1ubuntu0.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.12","version_link":"https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.15","pocket":"security"}],"resolute":[{"name":"python3.14","version":"3.14.4-1ubuntu0.1","description":"An interactive high-level object-oriented language","is_source":true},{"name":"idle-python3.14","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"libpython3.14","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"libpython3.14-dev","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"libpython3.14-minimal","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"libpython3.14-stdlib","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"libpython3.14-testsuite","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14-dev","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14-doc","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14-examples","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14-full","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14-gdbm","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14-minimal","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14-nopie","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14-tk","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"},{"name":"python3.14-venv","version":"3.14.4-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python3.14","version_link":"https://launchpad.net/ubuntu/+source/python3.14/3.14.4-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-9669","CVE-2026-6019","CVE-2026-3644","CVE-2025-13462","CVE-2026-7774","CVE-2021-4189","CVE-2026-4224","CVE-2026-1299","CVE-2026-0672","CVE-2026-3276","CVE-2026-4786","CVE-2026-1502","CVE-2025-69534","CVE-2026-2297","CVE-2026-8328","CVE-2026-6100","CVE-2026-5713","CVE-2026-4519"]}]},{"id":"CVE-2026-3497","published":"2026-03-12T18:00:00","updated_at":"2026-06-30T18:43:36.800998+00:00","description":"\nVulnerability in the OpenSSH GSSAPI delta included in various Linux\ndistributions. This vulnerability affects the GSSAPI patches added by\nvarious Linux distributions and does not affect the OpenSSH upstream\nproject itself. The usage of sshpkt_disconnect() on an error, which does\nnot terminate the process, allows an attacker to send an unexpected GSSAPI\nmessage type during the GSSAPI key exchange to the server, which will call\nthe underlying function and continue the execution of the program without\nsetting the related connection variables. As the variables are not\ninitialized to NULL the code later accesses those uninitialized variables,\naccessing random memory, which could lead to undefined behavior. The\nrecommended workaround is to use ssh_packet_disconnect() instead, which\ndoes terminate the process. The impact of the vulnerability depends heavily\non the compiler flag hardening configuration.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openssh-ssh1 is only provided for compatibility with old devices\nthat cannot be upgraded to modern protocols. We will not be\nproviding any security support for the openssh-ssh1 package as\nit is insecure and should be used in trusted environments only."},{"author":"ej7367","note":"bionic and older are not affected because they use\npacket_disconnect() (which then calls the correct\nssh_packet_disconnect() function)."}],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-3497","https://ubuntu.com/security/notices/USN-8090-1","https://ubuntu.com/security/notices/USN-8090-2"],"bugs":[""],"patches":{"openssh":[],"openssh-ssh1":[]},"tags":{},"packages":[{"name":"openssh","source":"https://ubuntu.com/security/cve?package=openssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh","debian":"https://tracker.debian.org/pkg/openssh","statuses":[{"release_codename":"resolute","status":"not-affected","description":"1:10.2p1-2ubuntu3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:8.2p1-4ubuntu0.13+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"1:8.9p1-3ubuntu0.14","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:9.6p1-3ubuntu13.15","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1:10.0p1-5ubuntu5.1","component":null,"pocket":"security"}]},{"name":"openssh-ssh1","source":"https://ubuntu.com/security/cve?package=openssh-ssh1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssh-ssh1","debian":"https://tracker.debian.org/pkg/openssh-ssh1","statuses":[{"release_codename":"resolute","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"frozen on openssh 7.5p","component":null,"pocket":"security"}]}],"notices_ids":["USN-8090-1","USN-8090-2"],"notices":[{"id":"USN-8090-1","title":"OpenSSH vulnerabilities","summary":"Several security issues were fixed in OpenSSH.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-12T18:16:18.075458","description":"Jeremy Brown discovered that the OpenSSH GSSAPI Key Exchange incorrectly\nhandled disconnecting clients. In non-default configurations where the\nGSSAPIKeyExchange setting is enabled, a remote attacker could use this\nissue to cause OpenSSH to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-3497)\n\nDavid Leadbeater discovered that OpenSSH incorrectly handled certain\ncontrol characters in usernames. When untrusted usernames and the\nProxyCommand are being used, an attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2025-61984)\n\nDavid Leadbeater discovered that OpenSSH incorrectly handled NULL\ncharacters in ssh:// URIs. When the ProxyCommand is being used, an attacker\ncould possibly use this issue to execute arbitrary code. (CVE-2025-61985)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssh","version":"1:8.9p1-3ubuntu0.14","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.9p1-3ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.14","pocket":"security"},{"name":"openssh-server","version":"1:8.9p1-3ubuntu0.14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.14","pocket":"security"},{"name":"openssh-sftp-server","version":"1:8.9p1-3ubuntu0.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.14","pocket":"security"},{"name":"openssh-tests","version":"1:8.9p1-3ubuntu0.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.14","pocket":"security"},{"name":"ssh","version":"1:8.9p1-3ubuntu0.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.14","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:8.9p1-3ubuntu0.14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:8.9p1-3ubuntu0.14","pocket":"security"}],"noble":[{"name":"openssh","version":"1:9.6p1-3ubuntu13.15","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:9.6p1-3ubuntu13.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.15","pocket":"security"},{"name":"openssh-server","version":"1:9.6p1-3ubuntu13.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.15","pocket":"security"},{"name":"openssh-sftp-server","version":"1:9.6p1-3ubuntu13.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.15","pocket":"security"},{"name":"openssh-tests","version":"1:9.6p1-3ubuntu13.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.15","pocket":"security"},{"name":"ssh","version":"1:9.6p1-3ubuntu13.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.15","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:9.6p1-3ubuntu13.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:9.6p1-3ubuntu13.15","pocket":"security"}],"questing":[{"name":"openssh","version":"1:10.0p1-5ubuntu5.1","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:10.0p1-5ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.1","pocket":"security"},{"name":"openssh-client-gssapi","version":"1:10.0p1-5ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.1","pocket":"security"},{"name":"openssh-server","version":"1:10.0p1-5ubuntu5.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.1","pocket":"security"},{"name":"openssh-server-gssapi","version":"1:10.0p1-5ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.1","pocket":"security"},{"name":"openssh-sftp-server","version":"1:10.0p1-5ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.1","pocket":"security"},{"name":"openssh-tests","version":"1:10.0p1-5ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.1","pocket":"security"},{"name":"ssh","version":"1:10.0p1-5ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.1","pocket":"security"},{"name":"ssh-askpass-gnome","version":"1:10.0p1-5ubuntu5.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":"https://launchpad.net/ubuntu/+source/openssh/1:10.0p1-5ubuntu5.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-61984","CVE-2026-3497","CVE-2025-61985"]},{"id":"USN-8090-2","title":"OpenSSH vulnerabilities","summary":"Several security issues were fixed in OpenSSH.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-12T18:31:57.632582","description":"USN-8090-1 fixed vulnerabilities in OpenSSH. This update provides the\ncorresponding updates for Ubuntu 20.04 LTS.\n\nOriginal advisory details:\n\nJeremy Brown discovered that the OpenSSH GSSAPI Key Exchange incorrectly\nhandled disconnecting clients. In non-default configurations where the\nGSSAPIKeyExchange setting is enabled, a remote attacker could use this\nissue to cause OpenSSH to crash, resulting in a denial of service, or\npossibly execute arbitrary code. (CVE-2026-3497)\n\nDavid Leadbeater discovered that OpenSSH incorrectly handled certain\ncontrol characters in usernames. When untrusted usernames and the\nProxyCommand are being used, an attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2025-61984)\n\nDavid Leadbeater discovered that OpenSSH incorrectly handled NULL\ncharacters in ssh:// URIs. When the ProxyCommand is being used, an attacker\ncould possibly use this issue to execute arbitrary code. (CVE-2025-61985)","is_hidden":false,"release_packages":{"focal":[{"name":"openssh","version":"1:8.2p1-4ubuntu0.13+esm1","description":"secure shell (SSH) for secure access to remote machines","is_source":true},{"name":"openssh-client","version":"1:8.2p1-4ubuntu0.13+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"openssh-server","version":"1:8.2p1-4ubuntu0.13+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"openssh-sftp-server","version":"1:8.2p1-4ubuntu0.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"openssh-tests","version":"1:8.2p1-4ubuntu0.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"ssh","version":"1:8.2p1-4ubuntu0.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"},{"name":"ssh-askpass-gnome","version":"1:8.2p1-4ubuntu0.13+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssh","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2025-61984","CVE-2026-3497","CVE-2025-61985"]}]},{"id":"CVE-2026-28356","published":"2026-03-12T17:16:00","updated_at":"2026-06-02T08:37:25.746337+00:00","description":"\nmultipart is a fast multipart/form-data parser for python. Prior to 1.2.2,\n1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py\nuses a regular expression with an ambiguous alternation, which can cause\nexponential backtracking (ReDoS) when parsing maliciously crafted HTTP or\nmultipart segment headers. This can be abused for denial of service (DoS)\nattacks against web applications using this library to parse request\nheaders or multipart/form-data streams. The issue is fixed in 1.2.2, 1.3.1\nand 1.4.0-dev.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-28356","https://github.com/defnull/multipart/security/advisories/GHSA-p2m9-wcp5-6qw3","https://ubuntu.com/security/notices/USN-8343-1"],"bugs":[""],"patches":{"multipart":[]},"tags":{},"packages":[{"name":"multipart","source":"https://ubuntu.com/security/cve?package=multipart","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=multipart","debian":"https://tracker.debian.org/pkg/multipart","statuses":[{"release_codename":"questing","status":"released","description":"1.2.1-2+deb13u1build0.25.10.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.3.0-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.1-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8343-1"],"notices":[{"id":"USN-8343-1","title":"multipart vulnerability","summary":"multipart could be made to use excessive resources if it received\nspecially crafted input.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-05-28T17:53:21.995655","description":"It was discovered that multipart had an ambiguous regular expression\nalternation when handling certain HTTP header values. A remote attacker\ncould possibly use this issue to cause multipart to use excessive\nresources, leading to a denial of service.","is_hidden":false,"release_packages":{"questing":[{"name":"multipart","version":"1.2.1-2+deb13u1build0.25.10.1","description":"library for handling multipart/form-data POST requests","is_source":true},{"name":"python3-multipart","version":"1.2.1-2+deb13u1build0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/multipart","version_link":"https://launchpad.net/ubuntu/+source/multipart/1.2.1-2+deb13u1build0.25.10.1","pocket":"security"}],"resolute":[{"name":"multipart","version":"1.3.0-3ubuntu0.1","description":"library for handling multipart/form-data POST requests","is_source":true},{"name":"python3-multipart","version":"1.3.0-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/multipart","version_link":"https://launchpad.net/ubuntu/+source/multipart/1.3.0-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-28356"]}]},{"id":"CVE-2026-27940","published":"2026-03-12T17:16:00","updated_at":"2026-03-18T12:17:04.104872+00:00","description":"\nllama.cpp is an inference of several LLM models in C/C++. Prior to b8146,\nthe gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer\noverflow, leading to an undersized heap allocation. Using the subsequent\nfread() writes 528+ bytes of attacker-controlled data past the buffer\nboundary. This is a bypass of a similar bug in the same file -\nCVE-2025-53630, but the fix overlooked some areas. This vulnerability is\nfixed in b8146.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-27940"],"bugs":[""],"patches":{"llama.cpp":[]},"tags":{},"packages":[{"name":"llama.cpp","source":"https://ubuntu.com/security/cve?package=llama.cpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=llama.cpp","debian":"https://tracker.debian.org/pkg/llama.cpp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-3099","published":"2026-03-12T14:16:00","updated_at":"2026-03-18T12:16:48.134003+00:00","description":"\nA flaw was found in Libsoup. The server-side digest authentication\nimplementation in the SoupAuthDomainDigest class does not properly track\nissued nonces or enforce the required incrementing nonce-count (nc)\nattribute. This vulnerability allows a remote attacker to capture a single\nvalid authentication header and replay it repeatedly. Consequently, the\nattacker can bypass authentication and gain unauthorized access to\nprotected resources, impersonating the legitimate user.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nPer libsoup developers, impact is quite limited"},{"author":"mdeslaur","note":"no fix from libsoup developers as of 2026-03-11"}],"codename":null,"priority":"low","cvss3":5.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-3099"],"bugs":["https://gitlab.gnome.org/GNOME/libsoup/-/issues/495"],"patches":{"libsoup2.4":[],"libsoup3":[]},"tags":{},"packages":[{"name":"libsoup2.4","source":"https://ubuntu.com/security/cve?package=libsoup2.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup2.4","debian":"https://tracker.debian.org/pkg/libsoup2.4","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2026-03-11]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2026-03-11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2026-03-11","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2026-03-11","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2026-03-11","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2026-03-11","component":null,"pocket":"security"},{"release_codename":"xenial","status":"deferred","description":"2026-03-11","component":null,"pocket":"security"}]},{"name":"libsoup3","source":"https://ubuntu.com/security/cve?package=libsoup3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libsoup3","debian":"https://tracker.debian.org/pkg/libsoup3","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was deferred [2026-03-11]","component":null,"pocket":"security"},{"release_codename":"resolute","status":"deferred","description":"2026-03-11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"deferred","description":"2026-03-11","component":null,"pocket":"security"},{"release_codename":"noble","status":"deferred","description":"2026-03-11","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4016","published":"2026-03-12T09:15:00","updated_at":"2026-08-17T19:19:41.740569+00:00","description":"\nA security vulnerability has been detected in GPAC 26.03-DEV. Affected by\nthis vulnerability is the function svgin_process of the file\nsrc/filters/load_svg.c of the component SVG Parser. The manipulation leads\nto out-of-bounds write. Local access is required to approach this attack.\nThe exploit has been disclosed publicly and may be used. The identifier of\nthe patch is 7618d7206cdeb3c28961dc97ab0ecabaff0c8af2. It is suggested to\ninstall a patch to address this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4016","https://github.com/gpac/gpac/issues/3468","https://github.com/gpac/gpac/commit/7618d7206cdeb3c28961dc97ab0ecabaff0c8af2","https://github.com/gpac/gpac/","https://github.com/user-attachments/files/25494042/poc_dims_oob.py","https://vuldb.com/?ctiid.350538","https://vuldb.com/?id.350538","https://vuldb.com/?submit.769798"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-4015","published":"2026-03-12T09:15:00","updated_at":"2026-08-17T19:16:37.162054+00:00","description":"\nA weakness has been identified in GPAC 26.03-DEV. Affected is the function\ntxtin_process_texml of the file src/filters/load_text.c of the component\nTeXML File Parser. Executing a manipulation can lead to stack-based buffer\noverflow. It is possible to launch the attack on the local host. The\nexploit has been made available to the public and could be used for\nattacks. This patch is called d29f6f1ada5cc284cdfa783b6f532c7d8bd049a5.\nApplying a patch is advised to resolve this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-4015","https://github.com/gpac/gpac/issues/3467","https://github.com/gpac/gpac/commit/d29f6f1ada5cc284cdfa783b6f532c7d8bd049a5","https://github.com/gpac/gpac/","https://github.com/gpac/gpac/issues/3467#issuecomment-3945864390","https://github.com/user-attachments/files/25493992/poc_texml_overflow.py","https://vuldb.com/?ctiid.350537","https://vuldb.com/?id.350537","https://vuldb.com/?submit.769797"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1182","published":"2026-03-12T02:15:00","updated_at":"2026-03-18T12:17:04.104872+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n8.14 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could\nhave allowed an authenticated user to gain unauthorized access to\nconfidential issue title created in public projects under certain\ncircumstances.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1182"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-43010","published":"2026-03-12T01:15:00","updated_at":"2026-04-01T04:12:33.351464+00:00","description":"\nThe issue was addressed with improved memory handling. This issue is fixed\nin iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS 16.7.15\nand iPadOS 16.7.15, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously\ncrafted web content may lead to memory corruption.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\nfocal and earlier. Marking as ignored.\nwpewebkit isn't used by anything of importance in the archive,\nexcept for cog, an example container for wpewebkit. There is no\npoint in attempting to backport newer wpewebkit versions to the\narchive. As such, marking as ignored.\nIt is not feasible to fix webkitgtk, qtwebkit-source, and\nqtwebkit-opensource-src. Marking them as ignored."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2023-43010","https://webkitgtk.org/security/WSA-2026-0001.html"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.44.3-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2.44.3-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.48.6-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.44.0","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-3994","published":"2026-03-12T00:00:00","updated_at":"2026-07-10T20:11:17.397181+00:00","description":"\nA vulnerability was detected in rui314 mold up to 2.40.4. This issue\naffects the function mold::ObjectFilemold::X86_64::initialize_sections of\nthe file src/input-files.cc of the component Object File Handler.\nPerforming a manipulation results in heap-based buffer overflow. Attacking\nlocally is a requirement. The exploit is now public and may be used. The\nproject was informed of the problem early through an issue report but has\nnot responded yet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-3994"],"bugs":[""],"patches":{"mold":[]},"tags":{},"packages":[{"name":"mold","source":"https://ubuntu.com/security/cve?package=mold","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mold","debian":"https://tracker.debian.org/pkg/mold","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-3979","published":"2026-03-12T00:00:00","updated_at":"2026-07-10T20:11:51.429506+00:00","description":"\nA flaw has been found in quickjs-ng quickjs up to 0.12.1. This affects the\nfunction js_iterator_concat_return of the file quickjs.c. This manipulation\ncauses use after free. The attack requires local access. The exploit has\nbeen published and may be used. Patch name:\ndaab4ad4bae4ef071ed0294618d6244e92def4cd. Applying a patch is the\nrecommended action to fix this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-3979"],"bugs":[""],"patches":{"quickjs":[]},"tags":{},"packages":[{"name":"quickjs","source":"https://ubuntu.com/security/cve?package=quickjs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=quickjs","debian":"https://tracker.debian.org/pkg/quickjs","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-28384","published":"2026-03-12T00:00:00","updated_at":"2026-09-14T09:54:26.116894+00:00","description":"\nAn improper sanitization of the compression_algorithm parameter in\nCanonical LXD allows an authenticated, unprivileged user to execute\ncommands as the LXD daemon on the LXD server via API calls to the image and\nbackup endpoints. This issue affected LXD from 4.12 through 6.6 and was\nfixed in the snap versions 5.0.6-e49d9f4 (channel 5.0/stable),\n5.21.4-1374f39 (channel 5.21/stable), and 6.7-1f11451 (channel 6.0 stable).\nThe channel 4.0/stable is not affected as it contains version 4.0.10.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.9,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},"baseScore":9.4,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-28384","https://github.com/canonical/lxd/security/advisories/GHSA-4rmf-rcp8-2r9g","https://github.com/canonical/lxd/commit/043696a13171ace7dd4c2b32d34ce039ab629052","https://github.com/canonical/lxd/commit/7046979645c2ce1b63b2f9e60ddf6cbc4c4b78f9","https://github.com/canonical/lxd/commit/b7b411caf5c4971bfe2386c72128f44d7e2aaf4f","https://discourse.ubuntu.com/t/lxd-authenticated-remote-code-execution-fixes-available/78365"],"bugs":[""],"patches":{"lxd":[]},"tags":{},"packages":[{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"xenial","status":"not-affected","description":"2.0.11-0ubuntu1~16.04.4+esm1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0.3-0ubuntu1~18.04.2+esm1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:0.10","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.7","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-2808","published":"2026-03-12T00:00:00","updated_at":"2026-03-18T12:17:19.588923+00:00","description":"\nHashiCorp Consul and Consul Enterprise 1.18.20 up to 1.21.10 and 1.22.4 are\nvulnerable to arbitrary file read when configured with Kubernetes\nauthentication. This vulnerability, CVE-2026-2808, is fixed in Consul\n1.18.21, 1.21.11 and 1.22.5.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-2808"],"bugs":[""],"patches":{"consul":[]},"tags":{},"packages":[{"name":"consul","source":"https://ubuntu.com/security/cve?package=consul","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=consul","debian":"https://tracker.debian.org/pkg/consul","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-31988","published":"2026-03-11T23:16:00","updated_at":"2026-07-10T20:04:08.373351+00:00","description":"\nyauzl (aka Yet Another Unzip Library) version 3.2.0 for Node.js contains an\noff-by-one error in the NTFS extended timestamp extra field parser within\nthe getLastModDate() function. The while loop condition checks cursor <\ndata.length + 4 instead of cursor + 4 <= data.length, allowing\nreadUInt16LE() to read past the buffer boundary. A remote attacker can\ncause a denial of service (process crash via ERR_OUT_OF_RANGE exception) by\nsending a crafted zip file with a malformed NTFS extra field. This affects\nany Node.js application that processes zip file uploads and calls\nentry.getLastModDate() on parsed entries. Fixed in version 3.2.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-31988"],"bugs":[""],"patches":{"node-yauzl":[]},"tags":{},"packages":[{"name":"node-yauzl","source":"https://ubuntu.com/security/cve?package=node-yauzl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=node-yauzl","debian":"https://tracker.debian.org/pkg/node-yauzl","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-3950","published":"2026-03-11T20:16:00","updated_at":"2026-06-19T12:52:52.108678+00:00","description":"\nA vulnerability was identified in strukturag libheif up to 1.21.2. This\nimpacts the function Track::load of the file libheif/sequences/track.cc of\nthe component stsz/stts. The manipulation leads to out-of-bounds read. The\nattack needs to be performed locally. The exploit is publicly available and\nmight be used. Applying a patch is the recommended action to fix this\nissue. The patch available is inofficial and not approved yet.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"as of 2026-04-21, the fix in pull 1721 has not been accepted by\nlibheif developers, but the following two commits appear to fix\na similar issue, perhaps they are the right fixes for this CVE:\nhttps://github.com/strukturag/libheif/commit/71755d3d41a117685a3274bdd1214fc50a760f20\nhttps://github.com/strukturag/libheif/commit/f20c81745e917b4c496615140385c86d7a2fa58d\nneed to validate with reproducer"}],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-3950","https://ubuntu.com/security/notices/USN-8454-1"],"bugs":["https://github.com/strukturag/libheif/issues/1715"],"patches":{"libheif":["upstream: https://github.com/strukturag/libheif/pull/1721","upstream: https://github.com/strukturag/libheif/commit/edc1250260ffcbaa9cf16a4158a982382d5f1348"]},"tags":{},"packages":[{"name":"libheif","source":"https://ubuntu.com/security/cve?package=libheif","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libheif","debian":"https://tracker.debian.org/pkg/libheif","statuses":[{"release_codename":"resolute","status":"released","description":"1.21.2-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.20.2-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.22.0","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-8454-1"],"notices":[{"id":"USN-8454-1","title":"libheif vulnerabilities","summary":"Several security issues were fixed in libheif.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-06-18T16:41:59.246250","description":"Elhanan Haenel discovered that libheif incorrectly handled certain\nmalformed HEIF sequence files. An attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 25.10\nand Ubuntu 26.04 LTS. (CVE-2026-32738)\n\nElhanan Haenel discovered that libheif incorrectly handled certain\nmalformed HEIF sequence files, leading to an infinite loop. An attacker\ncould possibly use this issue to cause libheif to use excessive\nresources, resulting in a denial of service. This issue only affected\nUbuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32739)\n\nElhanan Haenel discovered that libheif incorrectly handled certain\ncrafted HEIF/AVIF image files. An attacker could possibly use this issue\nto cause a denial of service or execute arbitrary code. This issue only\naffected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-32740)\n\nIt was discovered that libheif incorrectly handled certain crafted HEIF\nfiles containing mask images. An attacker could possibly use this issue to\ncause a denial of service or execute arbitrary code. This issue only\naffected Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS.\n(CVE-2026-32741)\n\nIt was discovered that libheif incorrectly handled certain crafted\ngrid-based HEIF/AVIF files. An attacker could possibly use this issue to\nobtain sensitive information. This issue only affected Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 25.10, and Ubuntu 26.04 LTS.\n(CVE-2026-32814)\n\nIt was discovered that libheif incorrectly handled certain crafted HEIF\nfiles when compositing overlay images. An attacker could possibly use this\nissue to cause a denial of service or obtain sensitive information.\n(CVE-2026-32882)\n\nIt was discovered that libheif incorrectly handled certain crafted\nfiles. An attacker could possibly use this issue to cause a denial of\nservice. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-3950)\n\nIt was discovered that libheif incorrectly handled certain malformed\nHEIF sequence files. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04\nLTS. (CVE-2026-41069)\n\nIt was discovered that libheif incorrectly handled certain crafted HEIF\nsequence files. An attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS.\n(CVE-2026-41071)","is_hidden":false,"release_packages":{"bionic":[{"name":"libheif","version":"1.1.0-2ubuntu0.1~esm3","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"libheif-dev","version":"1.1.0-2ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"libheif-examples","version":"1.1.0-2ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"libheif1","version":"1.1.0-2ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libheif","version":"1.6.1-1ubuntu0.1~esm3","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.6.1-1ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"heif-thumbnailer","version":"1.6.1-1ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"libheif-dev","version":"1.6.1-1ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"libheif-examples","version":"1.6.1-1ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"libheif1","version":"1.6.1-1ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"libheif","version":"1.12.0-2ubuntu0.1~esm3","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.12.0-2ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"heif-thumbnailer","version":"1.12.0-2ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"libheif-dev","version":"1.12.0-2ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"libheif-examples","version":"1.12.0-2ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"},{"name":"libheif1","version":"1.12.0-2ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"libheif","version":"1.17.6-1ubuntu4.4","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"heif-thumbnailer","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-dev","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-examples","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"},{"name":"libheif1","version":"1.17.6-1ubuntu4.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.17.6-1ubuntu4.4","pocket":"security"}],"questing":[{"name":"libheif","version":"1.20.2-1ubuntu0.4","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"heif-thumbnailer","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"heif-view","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-dev","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-examples","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif-plugins-all","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"},{"name":"libheif1","version":"1.20.2-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.20.2-1ubuntu0.4","pocket":"security"}],"resolute":[{"name":"libheif","version":"1.21.2-3ubuntu0.1","description":"An ISO/IEC 23008-12:2017 HEIF and AVIF file format decoder and encoder","is_source":true},{"name":"heif-gdk-pixbuf","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"heif-thumbnailer","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"heif-view","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-dev","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-examples","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-aomdec","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-aomenc","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-dav1d","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-ffmpegdec","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-j2kdec","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-j2kenc","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-jpegdec","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-jpegenc","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-kvazaar","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-libde265","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-rav1e","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-svtenc","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugin-x265","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif-plugins-all","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"},{"name":"libheif1","version":"1.21.2-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libheif","version_link":"https://launchpad.net/ubuntu/+source/libheif/1.21.2-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-32740","CVE-2026-3950","CVE-2026-41071","CVE-2026-32739","CVE-2026-32814","CVE-2026-32741","CVE-2026-32738","CVE-2026-32882","CVE-2026-41069"]}]},{"id":"CVE-2026-31958","published":"2026-03-11T20:16:00","updated_at":"2026-08-31T18:15:45.604013+00:00","description":"\nTornado is a Python web framework and asynchronous networking library. In\nversions of Tornado prior to 6.5.5, the only limit on the number of parts\nin multipart/form-data is the max_body_size setting (default 100MB). Since\nparsing occurs synchronously on the main thread, this creates the\npossibility of denial-of-service due to the cost of parsing very large\nmultipart bodies with many parts. This vulnerability is fixed in 6.5.5.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-31958","https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc","https://ubuntu.com/security/notices/USN-8198-1","https://ubuntu.com/security/notices/USN-8198-2"],"bugs":[""],"patches":{"python-tornado":["upstream: https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839"]},"tags":{},"packages":[{"name":"python-tornado","source":"https://ubuntu.com/security/cve?package=python-tornado","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-tornado","debian":"https://tracker.debian.org/pkg/python-tornado","statuses":[{"release_codename":"resolute","status":"released","description":"6.5.4-0.1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.5.3-1ubuntu0.2+esm3","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"6.0.3+really5.1.1-3ubuntu0.1~esm5","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"6.1.0-3ubuntu0.1~esm5","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"6.4.0-1ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"6.4.2-3ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.2.1-1ubuntu3.1+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"6.5.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8198-1","USN-8198-2"],"notices":[{"id":"USN-8198-1","title":"Tornado vulnerabilities","summary":"Several security issues were fixed in Tornado.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-04-22T17:52:30.470585","description":"It was discovered that Tornado incorrectly handled parsing of large\nmultipart request bodies. An attacker could possibly use this issue to\ncause a denial of service. (CVE-2026-31958)\n\nIt was discovered that Tornado did not properly validate characters in\ncookie values. An attacker could possibly use this issue to inject\narbitrary cookie attributes. (CVE-2026-35536)","is_hidden":false,"release_packages":{"bionic":[{"name":"python-tornado","version":"4.5.3-1ubuntu0.2+esm3","description":"scalable, non-blocking web server and tools","is_source":true},{"name":"python-tornado","version":"4.5.3-1ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":null,"pocket":"esm-apps"},{"name":"python-tornado-doc","version":"4.5.3-1ubuntu0.2+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":null,"pocket":"esm-apps"},{"name":"python3-tornado","version":"4.5.3-1ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"python-tornado","version":"6.0.3+really5.1.1-3ubuntu0.1~esm5","description":"scalable, non-blocking web server and tools","is_source":true},{"name":"python-tornado-doc","version":"6.0.3+really5.1.1-3ubuntu0.1~esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":null,"pocket":"esm-apps"},{"name":"python3-tornado","version":"6.0.3+really5.1.1-3ubuntu0.1~esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"python-tornado","version":"6.1.0-3ubuntu0.1~esm5","description":"scalable, non-blocking web server and tools","is_source":true},{"name":"python-tornado-doc","version":"6.1.0-3ubuntu0.1~esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":null,"pocket":"esm-apps"},{"name":"python3-tornado","version":"6.1.0-3ubuntu0.1~esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"python-tornado","version":"6.4.0-1ubuntu0.5","description":"scalable, non-blocking web server and tools","is_source":true},{"name":"python-tornado-doc","version":"6.4.0-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":"https://launchpad.net/ubuntu/+source/python-tornado/6.4.0-1ubuntu0.5","pocket":"security"},{"name":"python3-tornado","version":"6.4.0-1ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":"https://launchpad.net/ubuntu/+source/python-tornado/6.4.0-1ubuntu0.5","pocket":"security"}],"questing":[{"name":"python-tornado","version":"6.4.2-3ubuntu0.3","description":"scalable, non-blocking web server and tools","is_source":true},{"name":"python-tornado-doc","version":"6.4.2-3ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":"https://launchpad.net/ubuntu/+source/python-tornado/6.4.2-3ubuntu0.3","pocket":"security"},{"name":"python3-tornado","version":"6.4.2-3ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":"https://launchpad.net/ubuntu/+source/python-tornado/6.4.2-3ubuntu0.3","pocket":"security"}],"xenial":[{"name":"python-tornado","version":"4.2.1-1ubuntu3.1+esm3","description":"scalable, non-blocking web server and tools","is_source":true},{"name":"python-tornado","version":"4.2.1-1ubuntu3.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":null,"pocket":"esm-infra"},{"name":"python3-tornado","version":"4.2.1-1ubuntu3.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2026-31958","CVE-2026-35536"]},{"id":"USN-8198-2","title":"Tornado vulnerabilities","summary":"Several security issues were fixed in Tornado.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-04-28T19:27:53.439849","description":"USN-8198-1 fixed vulnerabilities in Tornado. This update provides the\ncorresponding updates for Ubuntu 26.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that Tornado incorrectly handled parsing of large\n multipart request bodies. An attacker could possibly use this issue to\n cause a denial of service. (CVE-2026-31958)\n\n It was discovered that Tornado did not properly validate characters in\n cookie values. An attacker could possibly use this issue to inject\n arbitrary cookie attributes. (CVE-2026-35536)","is_hidden":false,"release_packages":{"resolute":[{"name":"python-tornado","version":"6.5.4-0.1ubuntu0.1","description":"scalable, non-blocking web server and tools","is_source":true},{"name":"python-tornado-doc","version":"6.5.4-0.1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":"https://launchpad.net/ubuntu/+source/python-tornado/6.5.4-0.1ubuntu0.1","pocket":"security"},{"name":"python3-tornado","version":"6.5.4-0.1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-tornado","version_link":"https://launchpad.net/ubuntu/+source/python-tornado/6.5.4-0.1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-35536","CVE-2026-31958"]}]},{"id":"CVE-2026-31900","published":"2026-03-11T20:16:00","updated_at":"2026-07-10T19:59:09.316810+00:00","description":"\nBlack is the uncompromising Python code formatter. Black provides a GitHub\naction for formatting code. This action supports an option, use_pyproject:\ntrue, for reading the version of Black to use from the repository\npyproject.toml. A malicious pull request could edit pyproject.toml to use a\ndirect URL reference to a malicious repository. This could lead to\narbitrary code execution in the context of the GitHub Action. Attackers\ncould then gain access to secrets or permissions available in the context\nof the action. Version 26.3.0 fixes this vulnerability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-31900"],"bugs":[""],"patches":{"black":[]},"tags":{},"packages":[{"name":"black","source":"https://ubuntu.com/security/cve?package=black","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=black","debian":"https://tracker.debian.org/pkg/black","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":14840,"limit":20,"total_results":79316}