{"cves":[{"id":"CVE-2025-14560","published":"2026-02-11T00:00:00","updated_at":"2026-02-12T01:35:13.479119+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under\ncertain conditions could have allowed an authenticated user to perform\nunauthorized actions on behalf of another user by injecting malicious\ncontent into vulnerability code flow.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-14560","https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","https://gitlab.com/gitlab-org/gitlab/-/issues/583861","https://hackerone.com/reports/3461083"],"bugs":[""],"patches":{"gitlab":[],"gitlab-agent":[]},"tags":{},"packages":[{"name":"gitlab-agent","source":"https://ubuntu.com/security/cve?package=gitlab-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab-agent","debian":"https://tracker.debian.org/pkg/gitlab-agent","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-12575","published":"2026-02-11T00:00:00","updated_at":"2026-02-12T01:35:28.829173+00:00","description":"\nGitLab has remediated an issue in GitLab EE affecting all versions from\n18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under\ncertain conditions could have allowed an authenticated user with certain\npermissions to make unauthorized requests to internal network services\nthrough the GitLab server.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-12575","https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","https://gitlab.com/gitlab-org/gitlab/-/issues/579171","https://hackerone.com/reports/3397752"],"bugs":[""],"patches":{"gitlab":[],"gitlab-agent":[]},"tags":{},"packages":[{"name":"gitlab-agent","source":"https://ubuntu.com/security/cve?package=gitlab-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab-agent","debian":"https://tracker.debian.org/pkg/gitlab-agent","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-12474","published":"2026-02-11T00:00:00","updated_at":"2026-07-10T07:19:37.809183+00:00","description":"\nA specially-crafted file can cause libjxl's decoder to read pixel data from\nuninitialized (but allocated) memory.\nThis can be done by causing the decoder to reference an outside-image-bound\narea in a subsequent patches. An incorrect optimization causes the decoder\nto omit populating those areas.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nVulnerability enables reading uninitialized memory when decoding a specially crafted file"}],"codename":null,"priority":"low","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-12474","https://github.com/libjxl/libjxl/pull/4495"],"bugs":[""],"patches":{"graphicsmagick":[]},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-12073","published":"2026-02-11T00:00:00","updated_at":"2026-02-12T01:34:41.352549+00:00","description":"\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from\n18.0 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under\ncertain conditions, could have allowed an authenticated user to perform\nserver-side request forgery against internal services by bypassing\nprotections in the Git repository import functionality.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-12073","https://about.gitlab.com/releases/2026/02/10/patch-release-gitlab-18-8-4-released/","https://gitlab.com/gitlab-org/gitlab/-/issues/578091","https://hackerone.com/reports/3314987"],"bugs":[""],"patches":{"gitlab":[],"gitlab-agent":[]},"tags":{},"packages":[{"name":"gitlab-agent","source":"https://ubuntu.com/security/cve?package=gitlab-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab-agent","debian":"https://tracker.debian.org/pkg/gitlab-agent","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-26007","published":"2026-02-10T22:17:00","updated_at":"2026-09-11T07:08:09.258421+00:00","description":"\ncryptography is a package designed to expose cryptographic primitives and\nrecipes to Python developers. Prior to 46.0.5, the public_key_from_numbers\n(or EllipticCurvePublicNumbers.public_key()),\nEllipticCurvePublicNumbers.public_key(), load_der_public_key() and\nload_pem_public_key() functions do not verify that the point belongs to the\nexpected prime-order subgroup of the curve. This missing validation allows\nan attacker to provide a public key point P from a small-order subgroup.\nThis can lead to security issues in various situations, such as the most\ncommonly used signature verification (ECDSA) and shared key negotiation\n(ECDH). When the victim computes the shared secret as S =\n[victim_private_key]P via ECDH, this leaks information about\nvictim_private_key mod (small_subgroup_order). For curves with cofactor >\n1, this reveals the least significant bits of the private key. When these\nweak public keys are used in ECDSA , it's easy to forge signatures on the\nsmall subgroup. Only SECT curves are impacted by this. This vulnerability\nis fixed in 46.0.5.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Per upstream release notes: \"This issue only affects binary\nelliptic curves, which are rarely used in real-world\napplications.\"\nIn noble and earlier releases, the EC backend did not use rust,\nsee the following commit:\nhttps://github.com/pyca/cryptography/commit/f38eb4a0e45645e6a43f8dd589f1d3ce1103e83c"}],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-26007","https://github.com/pyca/cryptography/security/advisories/GHSA-r6ph-v2qm-q3c2","http://www.openwall.com/lists/oss-security/2026/02/10/4","https://ubuntu.com/security/notices/USN-8087-1","https://ubuntu.com/security/notices/USN-8087-3"],"bugs":[""],"patches":{"python-cryptography":["upstream: https://github.com/pyca/cryptography/commit/0eebb9dbb6343d9bc1d91e5a2482ed4e054a6d8c"]},"tags":{},"packages":[{"name":"python-cryptography","source":"https://ubuntu.com/security/cve?package=python-cryptography","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-cryptography","debian":"https://tracker.debian.org/pkg/python-cryptography","statuses":[{"release_codename":"resolute","status":"not-affected","description":"46.0.5-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.1.4-1ubuntu1.4+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2.8-3ubuntu0.3+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"1.2.3-1ubuntu0.3+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"46.0.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.4.8-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"41.0.7-4ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"43.0.0-1ubuntu1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8087-1","USN-8087-3"],"notices":[{"id":"USN-8087-1","title":"python-cryptography vulnerability","summary":"python-cryptography could be made to expose sensitive information over the\nnetwork.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-12T14:16:11.223826","description":"It was discovered that python-cryptography incorrectly handled subgroup\nvalidation for SECT curves. A remote attacker could use this issue to\nperform a subgroup attack and possibly recover the least significant bits\nof private keys.","is_hidden":false,"release_packages":{"jammy":[{"name":"python-cryptography","version":"3.4.8-1ubuntu2.3","description":"Cryptography Python library","is_source":true},{"name":"python-cryptography-doc","version":"3.4.8-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":"https://launchpad.net/ubuntu/+source/python-cryptography/3.4.8-1ubuntu2.3","pocket":"security"},{"name":"python3-cryptography","version":"3.4.8-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":"https://launchpad.net/ubuntu/+source/python-cryptography/3.4.8-1ubuntu2.3","pocket":"security"}],"noble":[{"name":"python-cryptography","version":"41.0.7-4ubuntu0.3","description":"Cryptography Python library","is_source":true},{"name":"python-cryptography-doc","version":"41.0.7-4ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":"https://launchpad.net/ubuntu/+source/python-cryptography/41.0.7-4ubuntu0.3","pocket":"security"},{"name":"python3-cryptography","version":"41.0.7-4ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":"https://launchpad.net/ubuntu/+source/python-cryptography/41.0.7-4ubuntu0.3","pocket":"security"}],"questing":[{"name":"python-cryptography","version":"43.0.0-1ubuntu1.1","description":"Cryptography Python library","is_source":true},{"name":"python-cryptography-doc","version":"43.0.0-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":"https://launchpad.net/ubuntu/+source/python-cryptography/43.0.0-1ubuntu1.1","pocket":"security"},{"name":"python3-cryptography","version":"43.0.0-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":"https://launchpad.net/ubuntu/+source/python-cryptography/43.0.0-1ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-26007"]},{"id":"USN-8087-3","title":"python-cryptography vulnerability","summary":"python-cryptography could be made to expose sensitive information over the\nnetwork.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-04-28T11:04:02.817438","description":"USN-8087-1 fixed a vulnerability in python-cryptography. This update\nprovides the corresponding update to Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,\nand Ubuntu 20.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that python-cryptography incorrectly handled subgroup\n validation for SECT curves. A remote attacker could use this issue to\n perform a subgroup attack and possibly recover the least significant bits\n of private keys.","is_hidden":false,"release_packages":{"bionic":[{"name":"python-cryptography","version":"2.1.4-1ubuntu1.4+esm3","description":"Cryptography Python library","is_source":true},{"name":"python-cryptography","version":"2.1.4-1ubuntu1.4+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"},{"name":"python-cryptography-doc","version":"2.1.4-1ubuntu1.4+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"},{"name":"python3-cryptography","version":"2.1.4-1ubuntu1.4+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"python-cryptography","version":"2.8-3ubuntu0.3+esm2","description":"Cryptography Python library","is_source":true},{"name":"python-cryptography","version":"2.8-3ubuntu0.3+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"},{"name":"python-cryptography-doc","version":"2.8-3ubuntu0.3+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"},{"name":"python3-cryptography","version":"2.8-3ubuntu0.3+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"python-cryptography","version":"1.2.3-1ubuntu0.3+esm3","description":"Cryptography Python library","is_source":true},{"name":"python-cryptography","version":"1.2.3-1ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"},{"name":"python-cryptography-doc","version":"1.2.3-1ubuntu0.3+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"},{"name":"python3-cryptography","version":"1.2.3-1ubuntu0.3+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-cryptography","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2026-26007"]}]},{"id":"CVE-2025-54514","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:40.895421+00:00","description":"\nImproper isolation of shared resources on a system on a chip by a malicious\nlocal attacker with high privileges could potentially lead to a partial\nloss of integrity.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"This is not planned to be fixed for the amd64-microcode\npackage in Ubuntu 14.04 as that release was already outside of the LTS\ntimeframe when this hardware platform was launched\nAMD released ucode patches for:\nAMD EPYC 9005 Series: C1:0x0B002151; B0:0x0B10104E\nThese two patches are included in upstream Version: 2025-07-29:\nMicrocode patches in microcode_amd_fam1ah.bin:\nFamily=0x1a Model=0x02 Stepping=0x01: Patch=0x0b002151 Length=14368 bytes\nFamily=0x1a Model=0x11 Stepping=0x00: Patch=0x0b10104e Length=14368 bytes"}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-54514","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4013.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=3768c184de68a85b9df6697e7f93a2f61de90a99"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.20251202.1ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.20251202.1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.20251202.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"no real-world users","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.20251202.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-52536","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:40.895421+00:00","description":"\nImproper Prevention of Lock Bit Modification in SEV firmware could allow a\nprivileged attacker to downgrade firmware potentially resulting in a loss\nof integrity.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"affects SEV FW, supported in microcode package\nstarting from noble\n\nAMD advisory mentions SEV release in:\nMilan (fam 19h model 01h): SEV FW 1.37.1F (1.55.31)\nGenoa (fam 19h model 11h): SEV FW 1.37.2B (1.55.43)\nTurin (fam 1a model 02h): SEV FW 1.37.3D (1.55.61)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 00h to 0fh.\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 10h to 1fh.\nUpdate AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors\nwith models in the range 00h to 0fh."}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-52536","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-52534","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:40.895421+00:00","description":"\nImproper bound check within AMD CPU microcode can allow a malicious guest\nto write to host memory, potentially resulting in loss of integrity.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"This is not planned to be fixed for the amd64-microcode package in Ubuntu\n14.04 as that release was already outside of the LTS timeframe when this\nhardware platform was launched\nAMD released ucode patches for:\nAMD EPYC 9005 Series: Dense B0:0x0B10104E.\nThis patch is included in upstream Version: 2025-07-29:\nMicrocode patches in microcode_amd_fam1ah.bin:\nFamily=0x1a Model=0x11 Stepping=0x00: Patch=0x0b10104e Length=14368 bytes"}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-52534","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=3768c184de68a85b9df6697e7f93a2f61de90a99"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.20251202.1ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.20251202.1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.20251202.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"no real-world users","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.20251202.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-48517","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:40.895421+00:00","description":"\nInsufficient Granularity of Access Control in SEV firmware could allow a\nprivileged user with a malicious hypervisor to create a SEV-ES guest with\nan ASID in the range meant for SEV-SNP guests potentially resulting in a\npartial loss of confidentiality.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"affects SEV FW, supported in microcode package\nstarting from noble\n\nAMD advisory mentions SEV release in:\nTurin (fam 1a model 02h): SEV FW 1.37.41 (1.55.65)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors\nwith models in the range 00h to 0fh."}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-48517","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-48514","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:40.895421+00:00","description":"\nInsufficient Granularity of Access Control in SEV firmware can allow a\nprivileged attacker to create a SEV-ES Guest to attack SNP guest,\npotentially resulting in a loss of confidentiality.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"This is not planned to be fixed for the amd64-microcode\npackage in Ubuntu 14.04 as that release was already outside of the LTS\ntimeframe when this hardware platform was launched\naffects ucode and SEV FW, the later is supported in\nmicrocode package starting from noble.\nAMD released ucode patches for:\nAMD EPYC™ 7003 Series: B1:0x0A0011DE; B2:0x0A001247\nAMD EPYC™ 8004/9004 Series (\"Bergamo\"/\"Siena\"): A2:0x0AA0021B\nAMD EPYC™ 9004 Series (\"Genoa\"): B1: 0x0A101156; B2:0x0A101251\nAMD EPYC™ 9005 Series: C1:0x0B002151; Dense B0: 0x0B10104E\nAll these patches are included in upstream Version: 2025-07-29:\nMicrocode patches in microcode_amd_fam19h.bin:\nFamily=0x19 Model=0x01 Stepping=0x01: Patch=0x0a0011de Length=5568 bytes\nFamily=0x19 Model=0x01 Stepping=0x02: Patch=0x0a001247 Length=5568 bytes\nFamily=0x19 Model=0xa0 Stepping=0x02: Patch=0x0aa0021c Length=5568 bytes\nFamily=0x19 Model=0x11 Stepping=0x01: Patch=0x0a101158 Length=5568 bytes\nFamily=0x19 Model=0x11 Stepping=0x02: Patch=0x0a101253 Length=5568 bytes\nMicrocode patches in microcode_amd_fam1ah.bin:\nFamily=0x1a Model=0x02 Stepping=0x01: Patch=0x0b002151 Length=14368 bytes\nFamily=0x1a Model=0x11 Stepping=0x00: Patch=0x0b10104e Length=14368 bytes\n\nAMD advisory mentions SEV release in:\nMilan (fam 19h model 01h): SEV FW 1.37.23 (1.55.35)\nGenoa (fam 19h model 11h): SEV FW 1.37.31 (1.55.49)\nTurin (fam 1a model 02h): SEV FW 1.37.41 (1.55.65)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 00h to 0fh.\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 10h to 1fh.\nUpdate AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors\nwith models in the range 00h to 0fh.\nAMD advertises that:\n\"Applying mitigation CVE-2025-48514 will result in disabling SEV-ES when\nSEV-SNP is enabled\""}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-48514","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=3768c184de68a85b9df6697e7f93a2f61de90a99","upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"no real-world users","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-48509","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:40.895421+00:00","description":"\nMissing Checks in certain functions related to RMP initialization can allow\na local admin privileged attacker to cause misidentification of I/O memory,\npotentially resulting in a loss of guest memory integrity","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"affects SEV FW, supported in microcode package\nstarting from noble\n\nAMD advisory mentions SEV release in:\nMilan (fam 19h model 01h): SEV FW 1.37.23 (1.55.35)\nGenoa (fam 19h model 11h): SEV FW 1.37.2A (1.55.42)\nTurin (fam 1a model 02h): SEV FW 1.37.3D (1.55.61)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 00h to 0fh.\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 10h to 1fh.\nUpdate AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors\nwith models in the range 00h to 0fh."}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":1.8,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-48509","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-29952","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:40.895421+00:00","description":"\nImproper Initialization within the AMD Secure Encrypted Virtualization\n(SEV) firmware can allow an admin privileged attacker to corrupt RMP\ncovered memory, potentially resulting in loss of guest memory integrity","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"affects SEV FW, supported in microcode package\nstarting from noble\n\nAMD advisory mentions SEV release in:\nTurin (fam 1a model 02h): SEV FW 1.37.41 (1.55.65)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors\nwith models in the range 00h to 0fh."}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-29952","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-29948","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:40.895421+00:00","description":"\nImproper access control in AMD Secure Encrypted Virtualization (SEV)\nfirmware could allow a malicious hypervisor to bypass RMP protections,\npotentially resulting in a loss of SEV-SNP guest memory integrity.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"affects SEV FW, supported in microcode package\nstarting from noble\n\nAMD advisory mentions SEV release in:\nTurin (fam 1a model 02h): SEV FW 1.37.41 (1.55.65)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors\nwith models in the range 00h to 0fh."}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-29948","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-29946","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:40.895421+00:00","description":"\nInsufficient or Incomplete Data Removal in Hardware Component in SEV\nfirmware doesn't fully flush IOMMU. This can potentially lead to a loss of\nconfidentiality and integrity in guest memory.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"affects SEV FW, supported in microcode package\nstarting from noble\n\nAMD advisory mentions SEV release in:\nTurin (fam 1a model 02h): SEV FW 1.37.41 (1.55.65)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors\nwith models in the range 00h to 0fh."}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":4.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-29946","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-29939","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:24.662830+00:00","description":"\nImproper access control in secure encrypted virtualization (SEV) could\nallow a privileged attacker to write to the reverse map page (RMP) during\nsecure nested paging (SNP) initialization, potentially resulting in a loss\nof guest memory confidentiality and integrity.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"affects SEV FW, supported in microcode package\nstarting from noble\n\nAMD advisory mentions SEV release in:\nMilan (fam 19h model 01h): SEV FW 1.37.23 (1.55.35)\nGenoa (fam 19h model 11h): SEV FW 1.37.31 (1.55.49)\nTurin (fam 1a model 02h): SEV FW 1.37.41 (1.55.65)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 00h to 0fh.\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 10h to 1fh.\nUpdate AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors\nwith models in the range 00h to 0fh."}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-29939","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-0031","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:24.662830+00:00","description":"\nA use after free in the SEV firmware could allow a malicous hypervisor to\nactivate a migrated guest with the SINGLE_SOCKET policy on a different\nsocket than the migration agent potentially resulting in loss of integrity.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"affects SEV FW, supported in microcode package\nstarting from noble\n\nAMD advisory mentions SEV release in:\nMilan (fam 19h model 01h): SEV FW 1.37.20 (1.55.32)\nGenoa (fam 19h model 11h): SEV FW 1.37.2B (1.55.43)\nTurin (fam 1a model 02h): SEV FW 1.37.3D (1.55.61)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 00h to 0fh.\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 10h to 1fh.\nUpdate AMD SEV firmware to version 1.58 build 3 for AMD family 1ah processors\nwith models in the range 00h to 0fh."}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":4.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-0031","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-0012","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:24.662830+00:00","description":"\nImproper handling of overlap between the segmented reverse map table (RMP)\nand system management mode (SMM) memory could allow a privileged attacker\ncorrupt or partially infer SMM memory resulting in loss of integrity or\nconfidentiality.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"This is not planned to be fixed for the amd64-microcode package in Ubuntu\n14.04 as that release was already outside of the LTS timeframe when this\nhardware platform was launched\nAMD released ucode patches for:\nAMD EPYC 9005 Series: C1:0x0B002147, Dense B0:0x0B101047.\nThese two patches are included in upstream Version: 2025-07-29:\nMicrocode patches in microcode_amd_fam1ah.bin:\nFamily=0x1a Model=0x02 Stepping=0x01: Patch=0x0b002151 Length=14368 bytes\nFamily=0x1a Model=0x11 Stepping=0x00: Patch=0x0b10104e Length=14368 bytes"}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-0012","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=3768c184de68a85b9df6697e7f93a2f61de90a99"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.20251202.1ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.20251202.1ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.20251202.1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"no real-world users","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.20251202.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-21953","published":"2026-02-10T20:16:00","updated_at":"2026-06-26T09:11:24.662830+00:00","description":"\nImproper input validation in IOMMU could allow a malicious hypervisor to\nreconfigure IOMMU registers resulting in loss of guest data integrity.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"affects SEV FW, supported in microcode package\nstarting from noble\n\nAMD advisory mentions SEV release in:\nBergamo/Siena (fam 19h model a0h): SEV FW 1.37.2A (1.55.42)\nGenoa (fam 19h model 11h): SEV FW 1.37.31 (1.55.49)\nUpstream including these versions is found in commit 13786e87:\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range 10h to 1fh.\nUpdate AMD SEV firmware to version 1.58 build 1 for AMD family 19h processors\nwith models in the range a0h to afh."}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"HIGH","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},"baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-21953","https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-3023.html"],"bugs":[""],"patches":{"amd64-microcode":["upstream: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git/commit/?id=13786e87c7e9bd3c90580f7a0ff8be602dbc6b60"]},"tags":{},"packages":[{"name":"amd64-microcode","source":"https://ubuntu.com/security/cve?package=amd64-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=amd64-microcode","debian":"https://tracker.debian.org/pkg/amd64-microcode","statuses":[{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25613","published":"2026-02-10T19:16:00","updated_at":"2026-02-19T19:51:19.451679+00:00","description":"\nAn authorized user may disable the MongoDB server by issuing a query\nagainst a collection that contains an invalid compound wildcard index.","ubuntu_description":"","notes":[{"author":"john-breton","note":"Patches were released after the switch to SSPL upstream,\nas such we cannot use them to patch Ubuntu releases.\n\nThe hope is a license-compliant third-party will make\npatches available in the future."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25613","https://jira.mongodb.org/browse/SERVER-113685"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/0a67bf09eb2d90e8826e6b3aad3fca0c7a607edd","upstream: https://github.com/mongodb/mongo/commit/29e14c65c1f20360ce1888a1711d6726aef7ead2"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.29, 8.0.18","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25610","published":"2026-02-10T19:16:00","updated_at":"2026-02-19T19:51:31.802416+00:00","description":"\nAn authorized user may trigger a server crash by running a $geoNear\npipeline with certain invalid index hints.","ubuntu_description":"","notes":[{"author":"john-breton","note":"Patches were released after the switch to SSPL upstream,\nas such we cannot use them to patch Ubuntu releases.\n\nThe hope is a license-compliant third-party will make\npatches available in the future."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25610","https://jira.mongodb.org/browse/SERVER-99119"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/0276362deafb9b64f0493ba51f2220f02c20a8a8","upstream: https://github.com/mongodb/mongo/commit/c107ca5ddacba85dbd1b7e3502bb6be71bffc2a4"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.29, 8.0.13","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":15500,"limit":20,"total_results":79316}