{"cves":[{"id":"CVE-2026-25609","published":"2026-02-10T19:16:00","updated_at":"2026-02-19T19:51:31.802416+00:00","description":"\nIncorrect validation of the profile command may result in the determination\nthat a request altering the 'filter' is read-only.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25609","https://jira.mongodb.org/browse/SERVER-112952"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/b0b7cf1198ac07554df160c9e57c5492aceb744f","upstream: https://github.com/mongodb/mongo/commit/74b142f6921ef02411d0f458fa79e8a9bc4cb6b7"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.29, 8.0.18","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25506","published":"2026-02-10T19:16:00","updated_at":"2026-02-12T22:51:25.987449+00:00","description":"\nMUNGE is an authentication service for creating and validating user\ncredentials. From 0.5 to 0.5.17, local attacker can exploit a buffer\noverflow vulnerability in munged (the MUNGE authentication daemon) to leak\ncryptographic key material from process memory. With the leaked key\nmaterial, the attacker could forge arbitrary MUNGE credentials to\nimpersonate any user (including root) to services that rely on MUNGE for\nauthentication. The vulnerability allows a buffer overflow by sending a\ncrafted message with an oversized address length field, corrupting munged's\ninternal state and enabling extraction of the MAC subkey used for\ncredential verification. This vulnerability is fixed in 0.5.18.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":7.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25506","https://github.com/dun/munge/security/advisories/GHSA-r9cr-jf4v-75gh","https://github.com/dun/munge/commit/bf40cc27c4ce8451d4b062c9de0b67ec40894812","https://github.com/dun/munge/releases/tag/munge-0.5.18","https://ubuntu.com/security/notices/USN-8040-1"],"bugs":[""],"patches":{"munge":["upstream: https://github.com/dun/munge/commit/bf40cc27c4ce8451d4b062c9de0b67ec40894812"]},"tags":{},"packages":[{"name":"munge","source":"https://ubuntu.com/security/cve?package=munge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=munge","debian":"https://tracker.debian.org/pkg/munge","statuses":[{"release_codename":"bionic","status":"released","description":"0.5.13-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"0.5.13-2ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"0.5.14-6ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.5.15-4ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"0.5.16-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.5.11-1ubuntu1.1+esm1","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"0.5.11-3ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"upstream","status":"released","description":"0.5.16-1.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8040-1"],"notices":[{"id":"USN-8040-1","title":"MUNGE vulnerability","summary":"MUNGE could be made to crash or run programs as your login if it opened a\nspecially crafted file.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-02-12T18:08:10.008051","description":"Titouan Lazard discovered that MUNGE contained an exploitable buffer\noverflow in munged (the MUNGE authentication daemon). A local attacker\ncould possibly use this issue to forge MUNGE credentials, leading to\narbitrary code execution.","is_hidden":false,"release_packages":{"bionic":[{"name":"munge","version":"0.5.13-1ubuntu0.1~esm1","description":"authentication service for credentials","is_source":true},{"name":"libmunge-dev","version":"0.5.13-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-apps"},{"name":"libmunge2","version":"0.5.13-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-apps"},{"name":"munge","version":"0.5.13-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"munge","version":"0.5.13-2ubuntu0.1~esm1","description":"authentication service for credentials","is_source":true},{"name":"libmunge-dev","version":"0.5.13-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-apps"},{"name":"libmunge2","version":"0.5.13-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-apps"},{"name":"munge","version":"0.5.13-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"munge","version":"0.5.14-6ubuntu0.1","description":"authentication service for credentials","is_source":true},{"name":"libmunge-dev","version":"0.5.14-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":"https://launchpad.net/ubuntu/+source/munge/0.5.14-6ubuntu0.1","pocket":"security"},{"name":"libmunge2","version":"0.5.14-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":"https://launchpad.net/ubuntu/+source/munge/0.5.14-6ubuntu0.1","pocket":"security"},{"name":"munge","version":"0.5.14-6ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":"https://launchpad.net/ubuntu/+source/munge/0.5.14-6ubuntu0.1","pocket":"security"}],"noble":[{"name":"munge","version":"0.5.15-4ubuntu0.1","description":"authentication service for credentials","is_source":true},{"name":"libmunge-dev","version":"0.5.15-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":"https://launchpad.net/ubuntu/+source/munge/0.5.15-4ubuntu0.1","pocket":"security"},{"name":"libmunge2","version":"0.5.15-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":"https://launchpad.net/ubuntu/+source/munge/0.5.15-4ubuntu0.1","pocket":"security"},{"name":"munge","version":"0.5.15-4ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":"https://launchpad.net/ubuntu/+source/munge/0.5.15-4ubuntu0.1","pocket":"security"}],"questing":[{"name":"munge","version":"0.5.16-1ubuntu0.1","description":"authentication service for credentials","is_source":true},{"name":"libmunge-dev","version":"0.5.16-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":"https://launchpad.net/ubuntu/+source/munge/0.5.16-1ubuntu0.1","pocket":"security"},{"name":"libmunge2","version":"0.5.16-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":"https://launchpad.net/ubuntu/+source/munge/0.5.16-1ubuntu0.1","pocket":"security"},{"name":"munge","version":"0.5.16-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":"https://launchpad.net/ubuntu/+source/munge/0.5.16-1ubuntu0.1","pocket":"security"}],"trusty":[{"name":"munge","version":"0.5.11-1ubuntu1.1+esm1","description":"authentication service for credentials","is_source":true},{"name":"libmunge-dev","version":"0.5.11-1ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmunge2","version":"0.5.11-1ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-infra-legacy"},{"name":"munge","version":"0.5.11-1ubuntu1.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"munge","version":"0.5.11-3ubuntu0.1+esm1","description":"authentication service for credentials","is_source":true},{"name":"libmunge-dev","version":"0.5.11-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-apps"},{"name":"libmunge2","version":"0.5.11-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-apps"},{"name":"munge","version":"0.5.11-3ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/munge","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-25506"]}]},{"id":"CVE-2026-2302","published":"2026-02-10T19:16:00","updated_at":"2026-07-10T19:33:46.378604+00:00","description":"\nUnder specific conditions when processing a maliciously crafted value of\ntype Hash r, Mongoid::Criteria.from_hash may allow for executing arbitrary\nRuby code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-2302","https://jira.mongodb.org/browse/MONGOID-5919"],"bugs":[""],"patches":{"ruby-mongo":[]},"tags":{},"packages":[{"name":"ruby-mongo","source":"https://ubuntu.com/security/cve?package=ruby-mongo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-mongo","debian":"https://tracker.debian.org/pkg/ruby-mongo","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1850","published":"2026-02-10T19:15:00","updated_at":"2026-02-19T19:51:19.451679+00:00","description":"\nComplex queries can cause excessive memory usage in MongoDB Query Planner\nresulting in an Out-Of-Memory Crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1850","https://jira.mongodb.org/browse/SERVER-114126"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/0ef9a57d3847b0de93262db83ec23914820291c7"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.0.18","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1849","published":"2026-02-10T19:15:00","updated_at":"2026-02-19T19:51:19.451679+00:00","description":"\nMongoDB Server may experience an out-of-memory failure while evaluating\nexpressions that produce deeply nested documents. The issue arises in\nrecursive functions because the server does not periodically check the\ndepth of the expression.","ubuntu_description":"","notes":[{"author":"john-breton","note":"Patches were released after the switch to SSPL upstream,\nas such we cannot use them to patch Ubuntu releases.\n\nThe hope is a license-compliant third-party will make\npatches available in the future."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1849","https://jira.mongodb.org/browse/SERVER-102364"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/108ace15aad7ef52ae035f2cebc7fe26ef2c553c","upstream: https://github.com/mongodb/mongo/commit/b3955bd193c5c722b9871f3bf4ba4395cf38becd"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.29, 8.0.18","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1848","published":"2026-02-10T19:15:00","updated_at":"2026-02-19T19:51:13.368582+00:00","description":"\nConnections received from the proxy port may not count towards total\naccepted connections, resulting in server crashes if the total number of\nconnections exceeds available resources. This only applies to connections\naccepted from the proxy port, pending the proxy protocol header.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1848","https://jira.mongodb.org/browse/SERVER-114695"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/a6a52ef77c125f06cf9967f09033267b741ec72f","upstream: https://github.com/mongodb/mongo/commit/9d713d14b38bc7773bcd6848f61163167c437dba"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.29, 8.0.18","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1847","published":"2026-02-10T19:15:00","updated_at":"2026-08-17T19:27:11.899893+00:00","description":"\nInserting certain large documents into a replica set could lead to replica\nset secondaries not being able to fetch the oplog from the primary. This\ncould stall replication inside the replica set leading to server crash.","ubuntu_description":"","notes":[{"author":"john-breton","note":"Patches were released after the switch to SSPL upstream,\nas such we cannot use them to patch Ubuntu releases.\n\nThe hope is a license-compliant third-party will make\npatches available in the future."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1847","https://jira.mongodb.org/browse/SERVER-113532"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/022a52269b6d4cc0d216d09c494ff9717ead03ac","upstream: https://github.com/mongodb/mongo/commit/b5d2f82e0f8b7b611661286ba2f99c56b5bf85d2"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"xenial","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.29, 8.0.18","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25646","published":"2026-02-10T18:16:00","updated_at":"2026-09-11T06:58:34.384283+00:00","description":"\nLIBPNG is a reference library for use in applications that read, create,\nand manipulate PNG (Portable Network Graphics) raster image files. Prior to\n1.6.55, an out-of-bounds read vulnerability exists in the\npng_set_quantize() API function. When the function is called with no\nhistogram and the number of colors in the palette is more than twice the\nmaximum supported by the user's display, certain palettes will cause the\nfunction to enter into an infinite loop that reads past the end of an\ninternal heap-allocated buffer. The images that trigger this vulnerability\nare valid per the PNG specification. This vulnerability is fixed in 1.6.55.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25646","https://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3","http://www.openwall.com/lists/oss-security/2026/02/09/7","https://ubuntu.com/security/notices/USN-8035-1","https://ubuntu.com/security/notices/USN-8039-1","https://ubuntu.com/security/notices/USN-8081-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1127566"],"patches":{"libpng":[],"libpng1.6":["upstream: https://github.com/pnggroup/libpng/commit/01d03b8453eb30ade759cd45c707e5a1c7277d88"],"firefox":[],"thunderbird":[],"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]},{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libpng","source":"https://ubuntu.com/security/cve?package=libpng","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng","debian":"https://tracker.debian.org/pkg/libpng","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.2.50-1ubuntu2.14.04.3+esm1","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.2.54-1ubuntu1.1+esm2","component":null,"pocket":"esm-infra"}]},{"name":"libpng1.6","source":"https://ubuntu.com/security/cve?package=libpng1.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpng1.6","debian":"https://tracker.debian.org/pkg/libpng1.6","statuses":[{"release_codename":"resolute","status":"released","description":"1.6.55-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.55","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.6.34-1ubuntu0.18.04.2+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.6.37-2ubuntu0.1~esm2","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"1.6.20-2ubuntu0.1~esm3","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1.6.37-3ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.6.43-5ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.6.50-1ubuntu0.4","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses system libpng","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-8035-1","USN-8039-1","USN-8081-1"],"notices":[{"id":"USN-8035-1","title":"libpng vulnerabilities","summary":"Several security issues were fixed in libpng.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-02-12T13:37:00.461457","description":"It was discovered that the libpng simplified API incorrectly processed\npalette PNG images with partial transparency and gamma correction. If a\nuser or automated system were tricked into opening a specially crafted PNG\nfile, an attacker could use this issue to cause libpng to crash, resulting\nin a denial of service. (CVE-2025-66293)\n\nPetr Simecek, Stanislav Fort and Pavel Kohout discovered that the libpng\nsimplified API incorrectly processed interlaced 16-bit PNGs with 8-bit\noutput format and non-minimal row strides. If a user or automated system\nwere tricked into opening a specially crafted PNG file, an attacker could\nuse this issue to cause libpng to crash, resulting in a denial of service.\n(CVE-2026-22695)\n\nCosmin Truta discovered that the libpng simplified API incorrectly handled\ninvalid row strides. If a user or automated system were tricked into\nopening a specially crafted PNG file, an attacker could use this issue to\ncause libpng to crash, resulting in a denial of service. This issue only\naffected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2026-22801)\n\nIt was discovered that the libpng simplified API incorrectly handled\nquantizing RGB images. If a user or automated system were tricked into\nopening a specially crafted PNG file, an attacker could use this issue to\ncause libpng to crash, resulting in a denial of service. (CVE-2026-25646)","is_hidden":false,"release_packages":{"bionic":[{"name":"libpng1.6","version":"1.6.34-1ubuntu0.18.04.2+esm2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng-dev","version":"1.6.34-1ubuntu0.18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-infra"},{"name":"libpng-tools","version":"1.6.34-1ubuntu0.18.04.2+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-infra"},{"name":"libpng16-16","version":"1.6.34-1ubuntu0.18.04.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"libpng1.6","version":"1.6.37-2ubuntu0.1~esm2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng-dev","version":"1.6.37-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-infra"},{"name":"libpng-tools","version":"1.6.37-2ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-infra"},{"name":"libpng16-16","version":"1.6.37-2ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libpng1.6","version":"1.6.20-2ubuntu0.1~esm3","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng16-16","version":"1.6.20-2ubuntu0.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-apps"},{"name":"libpng16-dev","version":"1.6.20-2ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-apps"},{"name":"libpng16-devtools","version":"1.6.20-2ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-apps"},{"name":"libpng16-tools","version":"1.6.20-2ubuntu0.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2025-66293","CVE-2026-22801","CVE-2026-25646","CVE-2026-22695"]},{"id":"USN-8039-1","title":"libpng vulnerability","summary":"libpng could be made to crash if it opened a specially crafted file.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-02-12T18:00:35.347236","description":"It was discovered that the libpng simplified API incorrectly handled\nquantizing RGB images. If a user or automated system were tricked into\nopening a specially crafted PNG file, an attacker could use this issue to\ncause libpng to crash, resulting in a denial of service.","is_hidden":false,"release_packages":{"jammy":[{"name":"libpng1.6","version":"1.6.37-3ubuntu0.4","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng-dev","version":"1.6.37-3ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":"https://launchpad.net/ubuntu/+source/libpng1.6/1.6.37-3ubuntu0.4","pocket":"security"},{"name":"libpng-tools","version":"1.6.37-3ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":"https://launchpad.net/ubuntu/+source/libpng1.6/1.6.37-3ubuntu0.4","pocket":"security"},{"name":"libpng16-16","version":"1.6.37-3ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":"https://launchpad.net/ubuntu/+source/libpng1.6/1.6.37-3ubuntu0.4","pocket":"security"}],"noble":[{"name":"libpng1.6","version":"1.6.43-5ubuntu0.5","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng-dev","version":"1.6.43-5ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":"https://launchpad.net/ubuntu/+source/libpng1.6/1.6.43-5ubuntu0.5","pocket":"security"},{"name":"libpng-tools","version":"1.6.43-5ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":"https://launchpad.net/ubuntu/+source/libpng1.6/1.6.43-5ubuntu0.5","pocket":"security"},{"name":"libpng16-16t64","version":"1.6.43-5ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":"https://launchpad.net/ubuntu/+source/libpng1.6/1.6.43-5ubuntu0.5","pocket":"security"}],"questing":[{"name":"libpng1.6","version":"1.6.50-1ubuntu0.4","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng-dev","version":"1.6.50-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":"https://launchpad.net/ubuntu/+source/libpng1.6/1.6.50-1ubuntu0.4","pocket":"security"},{"name":"libpng-tools","version":"1.6.50-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":"https://launchpad.net/ubuntu/+source/libpng1.6/1.6.50-1ubuntu0.4","pocket":"security"},{"name":"libpng16-16t64","version":"1.6.50-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng1.6","version_link":"https://launchpad.net/ubuntu/+source/libpng1.6/1.6.50-1ubuntu0.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-25646"]},{"id":"USN-8081-1","title":"libpng vulnerabilities","summary":"Several security issues were fixed in libpng.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-11T09:10:16.499009","description":"It was discovered that libpng did not properly handle memory when processing\ncertain PNG files. An attacker could possibly use this issue to cause libpng\nto crash, resulting in a denial of service, or disclose sensitive information.\n(CVE-2025-64505)\n\nJoshua Inscoe discovered that libpng did not properly handle memory when\nprocessing certain PNG files. An attacker could possibly use this issue\nto cause libpng to crash, resulting in a denial of service, disclose sensitive\ninformation, or execute arbitrary code. (CVE-2026-25646)","is_hidden":false,"release_packages":{"trusty":[{"name":"libpng","version":"1.2.50-1ubuntu2.14.04.3+esm1","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.50-1ubuntu2.14.04.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libpng12-dev","version":"1.2.50-1ubuntu2.14.04.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libpng3","version":"1.2.50-1ubuntu2.14.04.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libpng","version":"1.2.54-1ubuntu1.1+esm2","description":"PNG (Portable Network Graphics) file library","is_source":true},{"name":"libpng12-0","version":"1.2.54-1ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":null,"pocket":"esm-infra"},{"name":"libpng12-dev","version":"1.2.54-1ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":null,"pocket":"esm-infra"},{"name":"libpng3","version":"1.2.54-1ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libpng","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2025-64505","CVE-2026-25646"]}]},{"id":"CVE-2026-25612","published":"2026-02-10T18:16:00","updated_at":"2026-08-17T19:19:13.858310+00:00","description":"\nThe internal locking mechanism of the MongoDB server uses an internal\nencoding of the resources in order to choose what lock to take. Collections\nmay inadvertently collide with one another in this representation causing\nunavailability between them due to conflicting locks.","ubuntu_description":"","notes":[{"author":"john-breton","note":"Patches were released after the switch to SSPL upstream,\nas such we cannot use them to patch Ubuntu releases.\n\nThe hope is a license-compliant third-party will make\npatches available in the future."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25612","https://jira.mongodb.org/browse/SERVER-114838","https://jira.mongodb.org/browse/SERVER-115296"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/fcc42b7ec3535f23715ab776e78cde028a0e0a57","upstream: https://github.com/mongodb/mongo/commit/4d2dcf3b548c433af6836289905b1a19e8bccf79"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"xenial","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.29, 8.0.18","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2026-02-19","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25611","published":"2026-02-10T18:16:00","updated_at":"2026-03-27T21:14:39.196890+00:00","description":"\nA series of specifically crafted, unauthenticated messages can exhaust\navailable memory and crash a MongoDB server.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nA remote attacker can send an unauthenticated message which could lead to a denial of service."},{"author":"john-breton","note":"Patches were released after the switch to SSPL upstream,\nas such we cannot use them to patch Ubuntu releases.\n\nThe hope is a license-compliant third-party will make\npatches available in the future."},{"author":"ej7367","note":"Vulnerability relies on message compression functionality which is\nnot present in xenial and older."}],"codename":null,"priority":"high","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25611","https://jira.mongodb.org/browse/SERVER-116206","https://jira.mongodb.org/browse/SERVER-116210","https://jira.mongodb.org/browse/SERVER-116211","https://jira.mongodb.org/browse/SERVER-119396"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/f09dc30fe2160e3b3e75ca7544edc04781c4d46b","upstream: https://github.com/mongodb/mongo/commit/9407c10f5b690cfb2b05d48f7f269652a0ac97f3"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.31, 8.0.20","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2026-03-27","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2026-03-27","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"vulnerable code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"vulnerable code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-21537","published":"2026-02-10T18:16:00","updated_at":"2026-02-11T03:39:00.042340+00:00","description":"\nImproper control of generation of code ('code injection') in Microsoft\nDefender for Linux allows an unauthorized attacker to execute code over an\nadjacent network.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-21537","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21537"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-21242","published":"2026-02-10T18:16:00","updated_at":"2026-02-11T03:40:13.728585+00:00","description":"\nUse after free in Windows Subsystem for Linux allows an authorized attacker\nto elevate privileges locally.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-21242","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21242"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-21237","published":"2026-02-10T18:16:00","updated_at":"2026-02-11T03:35:39.998173+00:00","description":"\nConcurrent execution using shared resource with improper synchronization\n('race condition') in Windows Subsystem for Linux allows an authorized\nattacker to elevate privileges locally.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-21237","https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21237"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25530","published":"2026-02-10T17:16:00","updated_at":"2026-02-11T03:38:56.760442+00:00","description":"\nKanboard is project management software focused on Kanban methodology.\nPrior to 1.2.50, the getSwimlane API method lacks project-level\nauthorization, allowing authenticated users to access swimlane data from\nprojects they cannot access. This vulnerability is fixed in 1.2.50.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25530","https://github.com/kanboard/kanboard/security/advisories/GHSA-6rxw-vvvj-r93q","https://github.com/kanboard/kanboard/commit/c3d8d20e05322b09e036fed7afb57194d624a414","https://github.com/kanboard/kanboard/releases/tag/v1.2.50"],"bugs":[""],"patches":{"kanboard-cli":[],"python-kanboard":[]},"tags":{},"packages":[{"name":"python-kanboard","source":"https://ubuntu.com/security/cve?package=python-kanboard","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-kanboard","debian":"https://tracker.debian.org/pkg/python-kanboard","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kanboard-cli","source":"https://ubuntu.com/security/cve?package=kanboard-cli","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kanboard-cli","debian":"https://tracker.debian.org/pkg/kanboard-cli","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-24885","published":"2026-02-10T17:16:00","updated_at":"2026-02-11T03:38:41.368992+00:00","description":"\nKanboard is project management software focused on Kanban methodology.\nPrior to 1.2.50, a Cross-Site Request Forgery (CSRF) vulnerability exists\nin the ProjectPermissionController within the Kanboard application. The\napplication fails to strictly enforce the application/json Content-Type for\nthe changeUserRole action. Although the request body is JSON, the server\naccepts text/plain, allowing an attacker to craft a malicious form using\nthe text/plain attribute. Which allows unauthorized modification of project\nuser roles if an authenticated admin visits a malicious site This\nvulnerability is fixed in 1.2.50.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-24885","https://github.com/kanboard/kanboard/security/advisories/GHSA-582j-h4w4-hwr5","https://github.com/kanboard/kanboard/commit/2c56d92783d4a3094812c2f7cba50f80a372f95e","https://github.com/kanboard/kanboard/releases/tag/v1.2.50"],"bugs":[""],"patches":{"kanboard-cli":[],"python-kanboard":[]},"tags":{},"packages":[{"name":"python-kanboard","source":"https://ubuntu.com/security/cve?package=python-kanboard","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-kanboard","debian":"https://tracker.debian.org/pkg/python-kanboard","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kanboard-cli","source":"https://ubuntu.com/security/cve?package=kanboard-cli","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kanboard-cli","debian":"https://tracker.debian.org/pkg/kanboard-cli","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-31648","published":"2026-02-10T17:16:00","updated_at":"2026-03-03T19:44:31.857734+00:00","description":"\nImproper handling of values in the microcode flow for some Intel(R)\nProcessor Family may allow an escalation of privilege. Startup code and smm\nadversary with a privileged user combined with a high complexity attack may\nenable escalation of privilege. This result may potentially occur via local\naccess when attack requirements are present with special internal knowledge\nand requires no user interaction. The potential vulnerability may impact\nthe confidentiality (low), integrity (low) and availability (none) of the\nvulnerable system, resulting in subsequent system confidentiality (low),\nintegrity (low) and availability (none) impacts.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nHigh complexity local attack with special internal knowledge needed"},{"author":"rodrigo-zaiden","note":"trusty cannot use intel-microcode during early boot and is\ntherefore generally not updated."}],"codename":null,"priority":"low","cvss3":3.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-31648","https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260210-rev1","https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01396.html","https://ubuntu.com/security/notices/USN-8068-1"],"bugs":[""],"patches":{"intel-microcode":["upstream: https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/commit/b24397c3611f5b0a7ccb3071df99ba596721d82b"]},"tags":{},"packages":[{"name":"intel-microcode","source":"https://ubuntu.com/security/cve?package=intel-microcode","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=intel-microcode","debian":"https://tracker.debian.org/pkg/intel-microcode","statuses":[{"release_codename":"trusty","status":"ignored","description":"see Notes","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"20260210","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.20260210.0ubuntu0.18.04.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"3.20260210.0ubuntu0.20.04.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"3.20260210.0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.20260210.0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.20260210.0ubuntu0.25.10.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.20260210.0ubuntu0.16.04.1+esm1","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8068-1"],"notices":[{"id":"USN-8068-1","title":"Intel Microcode vulnerability","summary":"The system could be made to run programs as an administrator.","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.","references":[],"published":"2026-03-03T14:03:20.520125","description":"Sergiu Ghetie discovered that some IntelĀ® processors did not properly\nhandle values in the microcode flow. A local authenticated user could\npotentially use this issue to escalate their privileges.","is_hidden":false,"release_packages":{"bionic":[{"name":"intel-microcode","version":"3.20260210.0ubuntu0.18.04.1+esm1","description":"Processor microcode for Intel CPUs","is_source":true},{"name":"intel-microcode","version":"3.20260210.0ubuntu0.18.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/intel-microcode","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"intel-microcode","version":"3.20260210.0ubuntu0.20.04.1+esm1","description":"Processor microcode for Intel CPUs","is_source":true},{"name":"intel-microcode","version":"3.20260210.0ubuntu0.20.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/intel-microcode","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"intel-microcode","version":"3.20260210.0ubuntu0.22.04.1","description":"Processor microcode for Intel CPUs","is_source":true},{"name":"intel-microcode","version":"3.20260210.0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/intel-microcode","version_link":"https://launchpad.net/ubuntu/+source/intel-microcode/3.20260210.0ubuntu0.22.04.1","pocket":"security"}],"noble":[{"name":"intel-microcode","version":"3.20260210.0ubuntu0.24.04.1","description":"Processor microcode for Intel CPUs","is_source":true},{"name":"intel-microcode","version":"3.20260210.0ubuntu0.24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/intel-microcode","version_link":"https://launchpad.net/ubuntu/+source/intel-microcode/3.20260210.0ubuntu0.24.04.1","pocket":"security"}],"questing":[{"name":"intel-microcode","version":"3.20260210.0ubuntu0.25.10.1","description":"Processor microcode for Intel CPUs","is_source":true},{"name":"intel-microcode","version":"3.20260210.0ubuntu0.25.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/intel-microcode","version_link":"https://launchpad.net/ubuntu/+source/intel-microcode/3.20260210.0ubuntu0.25.10.1","pocket":"security"}],"xenial":[{"name":"intel-microcode","version":"3.20260210.0ubuntu0.16.04.1+esm1","description":"Processor microcode for Intel CPUs","is_source":true},{"name":"intel-microcode","version":"3.20260210.0ubuntu0.16.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/intel-microcode","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2025-31648"]}]},{"id":"CVE-2024-54192","published":"2026-02-10T16:16:00","updated_at":"2026-02-20T05:52:32.131600+00:00","description":"\nAn issue inTcpreplay v4.5.1 allows a local attacker to cause a denial of\nservice via a crafted file to the tcpedit_dlt_getplugin function at\nsrc/tcpedit/plugins/dlt_utils.c.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-54192","https://github.com/appneta/tcpreplay/issues/902","https://github.com/appneta/tcpreplay/pull/872"],"bugs":[""],"patches":{"tcpreplay":[]},"tags":{},"packages":[{"name":"tcpreplay","source":"https://ubuntu.com/security/cve?package=tcpreplay","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tcpreplay","debian":"https://tracker.debian.org/pkg/tcpreplay","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-15571","published":"2026-02-10T15:16:00","updated_at":"2026-09-11T06:56:45.107906+00:00","description":"\nA security vulnerability has been detected in ckolivas lrzip up to 0.651.\nThis vulnerability affects the function ucompthread of the file stream.c.\nSuch manipulation leads to null pointer dereference. The attack can only be\nperformed from a local environment. The exploit has been disclosed publicly\nand may be used. The project was informed of the problem early through an\nissue report but has not responded yet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-15571","https://github.com/ckolivas/lrzip/","https://github.com/ckolivas/lrzip/issues/263","https://github.com/user-attachments/files/21726331/PoC_NPD.zip","https://vuldb.com/?ctiid.344931","https://vuldb.com/?id.344931","https://vuldb.com/?submit.752603"],"bugs":[""],"patches":{"lrzip":[]},"tags":{},"packages":[{"name":"lrzip","source":"https://ubuntu.com/security/cve?package=lrzip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lrzip","debian":"https://tracker.debian.org/pkg/lrzip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-15570","published":"2026-02-10T14:16:00","updated_at":"2026-09-11T06:56:45.107906+00:00","description":"\nA vulnerability was found in ckolivas lrzip up to 0.651. This impacts the\nfunction lzma_decompress_buf of the file stream.c. Performing a\nmanipulation results in use after free. Attacking locally is a requirement.\nThe exploit has been made public and could be used. The project was\ninformed of the problem early through an issue report but has not responded\nyet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-15570","https://github.com/ckolivas/lrzip/","https://github.com/ckolivas/lrzip/issues/262","https://github.com/user-attachments/files/21709004/PoC_UAF.zip","https://vuldb.com/?ctiid.344926","https://vuldb.com/?id.344926","https://vuldb.com/?submit.752595"],"bugs":[""],"patches":{"lrzip":[]},"tags":{},"packages":[{"name":"lrzip","source":"https://ubuntu.com/security/cve?package=lrzip","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lrzip","debian":"https://tracker.debian.org/pkg/lrzip","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-15569","published":"2026-02-10T11:16:00","updated_at":"2026-07-10T21:25:40.040608+00:00","description":"\nA flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The\nimpacted element is the function get_system_dpi of the file\nplatform/x11/win_main.c. This manipulation causes uncontrolled search path.\nThe attack requires local access. The attack is considered to have high\ncomplexity. The exploitability is regarded as difficult. Upgrading to\nversion 1.26.2 is sufficient to resolve this issue. Patch name:\nebb125334eb007d64e579204af3c264aadf2e244. Upgrading the affected component\nis recommended.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.0,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-15569","https://artifex.com/","https://casper.mupdf.com/downloads/archive/mupdf-1.26.2-windows.zip","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=ebb125334eb007d64e579204af3c264aadf2e244","https://vuldb.com/?ctiid.344924","https://vuldb.com/?id.344924","https://vuldb.com/?submit.750978"],"bugs":[""],"patches":{"mupdf":[]},"tags":{},"packages":[{"name":"mupdf","source":"https://ubuntu.com/security/cve?package=mupdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mupdf","debian":"https://tracker.debian.org/pkg/mupdf","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was ignored [affects only Windows]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"affects only Windows","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"affects only Windows","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"affects only Windows","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"affects only Windows","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.26.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [affects only Windows]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":15520,"limit":20,"total_results":79316}