{"cves":[{"id":"CVE-2026-24095","published":"2026-02-09T16:16:00","updated_at":"2026-08-17T15:57:23.861890+00:00","description":"\nImproper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21,\n2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the \"Use WATO\"\npermission to access the \"Analyze configuration\" page by directly\nnavigating to its URL, bypassing the intended \"Access analyze\nconfiguration\" permission check. If these users also have the \"Make\nchanges, perform actions\" permission, they can perform unauthorized actions\nsuch as disabling checks or acknowledging results.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-24095","https://checkmk.com/werk/19032"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-24027","published":"2026-02-09T15:16:00","updated_at":"2026-02-11T03:40:13.728585+00:00","description":"\nCrafted zones can lead to increased incoming network traffic.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-24027","https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-01.html","https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-01.html"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1127490"],"patches":{"pdns-recursor":[]},"tags":{},"packages":[{"name":"pdns-recursor","source":"https://ubuntu.com/security/cve?package=pdns-recursor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdns-recursor","debian":"https://tracker.debian.org/pkg/pdns-recursor","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-0398","published":"2026-02-09T15:16:00","updated_at":"2026-02-11T03:38:00.818629+00:00","description":"\nCrafted zones can lead to increased resource usage and crafted CNAME chains\ncan lead to cache poisoning in Recursor.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-0398","https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-01.html","https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2026-01.html"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1127490"],"patches":{"pdns-recursor":[]},"tags":{},"packages":[{"name":"pdns-recursor","source":"https://ubuntu.com/security/cve?package=pdns-recursor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdns-recursor","debian":"https://tracker.debian.org/pkg/pdns-recursor","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-59024","published":"2026-02-09T15:16:00","updated_at":"2026-02-11T03:39:03.760863+00:00","description":"\nCrafted delegations or IP fragments can poison cached delegations in\nRecursor.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-59024","https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2025-06.html"],"bugs":[""],"patches":{"pdns-recursor":[]},"tags":{},"packages":[{"name":"pdns-recursor","source":"https://ubuntu.com/security/cve?package=pdns-recursor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdns-recursor","debian":"https://tracker.debian.org/pkg/pdns-recursor","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-59023","published":"2026-02-09T15:16:00","updated_at":"2026-02-11T03:36:43.962356+00:00","description":"\nCrafted delegations or IP fragments can poison cached delegations in\nRecursor.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-59023","https://docs.powerdns.com/recursor/security-advisories/powerdns-advisory-2025-06.html"],"bugs":[""],"patches":{"pdns-recursor":[]},"tags":{},"packages":[{"name":"pdns-recursor","source":"https://ubuntu.com/security/cve?package=pdns-recursor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pdns-recursor","debian":"https://tracker.debian.org/pkg/pdns-recursor","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-14831","published":"2026-02-09T15:16:00","updated_at":"2026-07-06T16:23:25.193395+00:00","description":"\nA flaw was found in GnuTLS. This vulnerability allows a denial of service\n(DoS) by excessive CPU (Central Processing Unit) and memory consumption via\nspecially crafted malicious certificates containing a large number of name\nconstraints and subject alternative names (SANs).","ubuntu_description":"","notes":[{"author":"mrmajumder","note":"esm-infra-legacy/xenial (gnutls28 3.4.10) is not-affected: its\nlib/x509/name_constraints.c has no name-constraint intersection\nlogic at all (no _gnutls_name_constraints_intersect /\nname_constraints_node_list_intersect), only flat per-name checks\n(check_dns_constraints)."}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-14831","https://access.redhat.com/security/cve/CVE-2025-14831","https://ubuntu.com/security/notices/USN-8043-1","https://ubuntu.com/security/notices/USN-8502-1"],"bugs":["https://gitlab.com/gnutls/gnutls/-/issues/1773","https://bugzilla.redhat.com/show_bug.cgi?id=2423177"],"patches":{"gnutls28":["upstream: https://gitlab.com/gnutls/gnutls/-/commit/0b2377dfccd99be641bf3f1a0de9f0dc8dc0d4b1","upstream: https://gitlab.com/gnutls/gnutls/-/commit/85d6348a30c74d4ee3710e0f4652f634eaad6914","upstream: https://gitlab.com/gnutls/gnutls/-/commit/c28475413f82e1f34295d5c039f0c0a4ca2ee526","upstream: https://gitlab.com/gnutls/gnutls/-/commit/6db7da7fcfe230f445b1edbb56e2a8346120c891","upstream: https://gitlab.com/gnutls/gnutls/-/commit/094accd3ebec17ead6c391757eaa18763b72d83f","upstream: https://gitlab.com/gnutls/gnutls/-/commit/bc62fbb946085527b4b1c02f337dd10c68c54690","upstream: https://gitlab.com/gnutls/gnutls/-/commit/80db5e90fa18d3e34bb91dd027bdf76d31e93dcd","upstream: https://gitlab.com/gnutls/gnutls/-/commit/d0ac999620c8c0aeb6939e1e92d884ca8e40b759","upstream: https://gitlab.com/gnutls/gnutls/-/commit/d6054f0016db05fb5c82177ddbd0a4e8331059a1"]},"tags":{},"packages":[{"name":"gnutls28","source":"https://ubuntu.com/security/cve?package=gnutls28","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gnutls28","debian":"https://tracker.debian.org/pkg/gnutls28","statuses":[{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.5.18-1ubuntu1.6+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"3.6.13-2ubuntu1.12+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"3.8.12-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.7.3-4ubuntu1.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.8.3-1.1ubuntu3.5","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.8.9-3ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"3.8.12-2ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8043-1","USN-8502-1"],"notices":[{"id":"USN-8043-1","title":"GnuTLS vulnerabilities","summary":"Several security issues were fixed in GnuTLS.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-02-16T13:53:33.815950","description":"Tim Scheckenbach discovered that GnuTLS incorrectly handled malicious\ncertificates containing a large number of name constraints and subject\nalternative names. A remote attacker could possibly use this issue to\ncause GnuTLS to consume resources, resulting in a denial of service.\n(CVE-2025-14831)\n\nLuigino Camastra discovered that GnuTLS incorrectly handled certain PKCS11\ntoken labels. A remote attacker could use this issue to cause GnuTLS to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. The default compiler options for affected releases should reduce the\nvulnerability to a denial of service. (CVE-2025-9820)","is_hidden":false,"release_packages":{"jammy":[{"name":"gnutls28","version":"3.7.3-4ubuntu1.8","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.7.3-4ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.8","pocket":"security"},{"name":"gnutls-doc","version":"3.7.3-4ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.8","pocket":"security"},{"name":"guile-gnutls","version":"3.7.3-4ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.8","pocket":"security"},{"name":"libgnutls-dane0","version":"3.7.3-4ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.8","pocket":"security"},{"name":"libgnutls-openssl27","version":"3.7.3-4ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.8","pocket":"security"},{"name":"libgnutls28-dev","version":"3.7.3-4ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.8","pocket":"security"},{"name":"libgnutls30","version":"3.7.3-4ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.8","pocket":"security"},{"name":"libgnutlsxx28","version":"3.7.3-4ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.7.3-4ubuntu1.8","pocket":"security"}],"noble":[{"name":"gnutls28","version":"3.8.3-1.1ubuntu3.5","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.8.3-1.1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.5","pocket":"security"},{"name":"gnutls-doc","version":"3.8.3-1.1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.5","pocket":"security"},{"name":"libgnutls-dane0t64","version":"3.8.3-1.1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.5","pocket":"security"},{"name":"libgnutls-openssl27t64","version":"3.8.3-1.1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.5","pocket":"security"},{"name":"libgnutls28-dev","version":"3.8.3-1.1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.5","pocket":"security"},{"name":"libgnutls30t64","version":"3.8.3-1.1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.3-1.1ubuntu3.5","pocket":"security"}],"questing":[{"name":"gnutls28","version":"3.8.9-3ubuntu2.1","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.8.9-3ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.1","pocket":"security"},{"name":"gnutls-doc","version":"3.8.9-3ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.1","pocket":"security"},{"name":"libgnutls-dane0t64","version":"3.8.9-3ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.1","pocket":"security"},{"name":"libgnutls-openssl27t64","version":"3.8.9-3ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.1","pocket":"security"},{"name":"libgnutls28-dev","version":"3.8.9-3ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.1","pocket":"security"},{"name":"libgnutls30t64","version":"3.8.9-3ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":"https://launchpad.net/ubuntu/+source/gnutls28/3.8.9-3ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-14831","CVE-2025-9820"]},{"id":"USN-8502-1","title":"GnuTLS vulnerabilities","summary":"Several security issues were fixed in GnuTLS.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-07-06T13:37:09.835289","description":"It was discovered that GnuTLS had a timing side-channel when processing\nmalformed ciphertexts in RSA-PSK ClientKeyExchange. A remote attacker\ncould possibly use this issue to recover sensitive information. This\nissue only affected Ubuntu 18.04 LTS. (CVE-2024-0553)\n\nBing Shi discovered that GnuTLS incorrectly handled decoding certain\nDER-encoded certificates. A remote attacker could possibly use this\nissue to cause GnuTLS to consume resources, leading to a denial of\nservice. This issue only affected Ubuntu 18.04 LTS. (CVE-2024-12243)\n\nLuigino Camastra discovered that GnuTLS incorrectly handled certain\nPKCS11 token labels. A remote attacker could use this issue to cause\nGnuTLS to crash, resulting in a denial of service, or possibly execute\narbitrary code. The default compiler options for affected releases\nshould reduce the vulnerability to a denial of service. (CVE-2025-9820)\n\nTim Scheckenbach discovered that GnuTLS incorrectly handled malicious\ncertificates containing a large number of name constraints and subject\nalternative names. A remote attacker could possibly use this issue to\ncause GnuTLS to consume resources, resulting in a denial of service.\nThis issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2025-14831)\n\nOleh Konko and Joshua Rogers discovered that GnuTLS did not properly\nhandle case-insensitive name constraints in certain cases. A remote\nattacker could possibly use this issue to bypass certificate validation,\nleading to a machine-in-the-middle attack. (CVE-2026-3833)\n\nJoshua Rogers discovered that GnuTLS did not properly handle very short\npremaster secrets in certain RSA key exchange cases with PKCS#11-backed\nserver keys. A remote attacker could possibly use this issue to obtain\nsensitive information. This issue only affected Ubuntu 18.04 LTS and\nUbuntu 20.04 LTS. (CVE-2026-5260)\n\nJoshua Rogers discovered that GnuTLS did not properly handle malformed\nDTLS handshake fragments in certain cases. A remote attacker could\npossibly use this issue to obtain sensitive information, or cause a\ndenial of service. This issue only affected Ubuntu 20.04 LTS.\n(CVE-2026-33845)\n\nHaruto Kimura, Oscar Reparaz, and Zou Dikai discovered that GnuTLS did\nnot properly validate DTLS handshake fragment lengths in certain cases.\nA remote attacker could possibly use this issue to cause GnuTLS to\ncrash, resulting in a denial of service, or execute arbitrary code.\n(CVE-2026-33846)\n\nJoshua Rogers discovered that GnuTLS did not properly order DTLS packets\nwith duplicate sequence numbers in certain cases. A remote attacker\ncould possibly use this issue to cause GnuTLS to crash, resulting in a\ndenial of service. (CVE-2026-42009)\n\nJoshua Rogers discovered that GnuTLS did not properly handle usernames\ncontaining NUL characters in certain RSA-PSK configurations. A remote\nattacker could possibly use this issue to bypass authentication and gain\nunintended access to services. This issue only affected Ubuntu 20.04\nLTS. (CVE-2026-42010)","is_hidden":false,"release_packages":{"bionic":[{"name":"gnutls28","version":"3.5.18-1ubuntu1.6+esm3","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.5.18-1ubuntu1.6+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"gnutls-doc","version":"3.5.18-1ubuntu1.6+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutls-dane0","version":"3.5.18-1ubuntu1.6+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutls-openssl27","version":"3.5.18-1ubuntu1.6+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutls28-dev","version":"3.5.18-1ubuntu1.6+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutls30","version":"3.5.18-1ubuntu1.6+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutlsxx28","version":"3.5.18-1ubuntu1.6+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"gnutls28","version":"3.6.13-2ubuntu1.12+esm2","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.6.13-2ubuntu1.12+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"gnutls-doc","version":"3.6.13-2ubuntu1.12+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"guile-gnutls","version":"3.6.13-2ubuntu1.12+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutls-dane0","version":"3.6.13-2ubuntu1.12+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutls-openssl27","version":"3.6.13-2ubuntu1.12+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutls28-dev","version":"3.6.13-2ubuntu1.12+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutls30","version":"3.6.13-2ubuntu1.12+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"},{"name":"libgnutlsxx28","version":"3.6.13-2ubuntu1.12+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"gnutls28","version":"3.4.10-4ubuntu1.9+esm3","description":"GNU TLS library","is_source":true},{"name":"gnutls-bin","version":"3.4.10-4ubuntu1.9+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra-legacy"},{"name":"gnutls-doc","version":"3.4.10-4ubuntu1.9+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra-legacy"},{"name":"guile-gnutls","version":"3.4.10-4ubuntu1.9+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgnutls-dev","version":"3.4.10-4ubuntu1.9+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgnutls-openssl27","version":"3.4.10-4ubuntu1.9+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgnutls28-dev","version":"3.4.10-4ubuntu1.9+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgnutls30","version":"3.4.10-4ubuntu1.9+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgnutlsxx28","version":"3.4.10-4ubuntu1.9+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gnutls28","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-33846","CVE-2026-3833","CVE-2026-42009","CVE-2026-5260","CVE-2026-33845","CVE-2024-12243","CVE-2025-14831","CVE-2025-9820","CVE-2026-42010","CVE-2024-0553"]}]},{"id":"CVE-2026-23903","published":"2026-02-09T10:15:00","updated_at":"2026-09-16T10:38:49.921902+00:00","description":"\nAuthentication Bypass by Alternate Name vulnerability in Apache Shiro.\nThis issue affects Apache Shiro: before 2.0.7.\nUsers are recommended to upgrade to version 2.0.7, which fixes the issue.\nThe issue only effects static files. If static files are served from a\ncase-insensitive filesystem,\nsuch as default macOS setup, static files may be accessed by varying the\ncase of the filename in the request.\nIf only lower-case (common default) filters are present in Shiro, they may\nbe bypassed this way.\nShiro 2.1.0 and later has a new parameters to remediate this issue\nshiro.ini: filterChainResolver.caseInsensitive = true\napplication.properties: shiro.caseInsensitive=true\nShiro 3.0.0 and later makes this the default in shiro.ini-based\nconfigurations.\nShiro 3.0.1 and later makes this the default in all configurations,\nincluding programmatic and Spring / Spring Boot.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23903","https://www.openwall.com/lists/oss-security/2026/02/08/1","https://lists.apache.org/thread/5jjf0hnjcol58z2m5y255c7scz1lnp8k","http://www.openwall.com/lists/oss-security/2026/02/08/1"],"bugs":[""],"patches":{"shiro":[]},"tags":{},"packages":[{"name":"shiro","source":"https://ubuntu.com/security/cve?package=shiro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=shiro","debian":"https://tracker.debian.org/pkg/shiro","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25916","published":"2026-02-09T09:16:00","updated_at":"2026-04-29T15:18:28.723325+00:00","description":"\nRoundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when \"Block remote\nimages\" is used, does not block SVG feImage.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25916","https://roundcube.net/news/2026/02/08/security-updates-1.6.13-and-1.5.13","https://nullcathedral.com/posts/2026-02-08-roundcube-svg-feimage-remote-image-bypass/","https://github.com/roundcube/roundcubemail/commit/26d7677","https://news.ycombinator.com/item?id=46937012","https://ubuntu.com/security/notices/USN-8223-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1127447"],"patches":{"roundcube":[]},"tags":{},"packages":[{"name":"roundcube","source":"https://ubuntu.com/security/cve?package=roundcube","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=roundcube","debian":"https://tracker.debian.org/pkg/roundcube","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.6.13+dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.3.6+dfsg.1-1ubuntu0.1~esm8","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.4.3+dfsg.1-1ubuntu0.1~esm8","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"1.5.0+dfsg.1-2ubuntu0.1~esm6","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"1.6.6+dfsg-2ubuntu0.1+esm3","component":null,"pocket":"esm-apps"}]}],"notices_ids":["USN-8223-1"],"notices":[{"id":"USN-8223-1","title":"Roundcube Webmail vulnerabilities","summary":"Several security issues were fixed in Roundcube Webmail.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-04-29T13:50:15.863721","description":"It was discovered that Roundcube Webmail mishandled Punycode xn-- domain names.\nAn attacker could possibly use this issue to cause a homograph attack. (CVE-2019-15237)\n\nIt was discovered that Roundcube Webmail did not properly sanitize certain\nattributes when handling CSS within HTML messages and certain SVG attributes.\nAn attacker could possibly use this issue to cause a cross-site scripting attack.\n(CVE-2024-38356, CVE-2024-38357)\n\nIt was discovered that Roundcube Webmail did not properly sanitize certain HTML\nattributes when rendering e-mail messages. An attacker could possibly use this\nissue to cause a cross-site scripting attack. (CVE-2024-42008)\n\nIt was discovered that Roundcube Webmail did not properly filter certain CSS token\nsequences within rendered e-mail messages. An attacker could possibly use this\nissue to obtain sensitive information. (CVE-2024-42010)\n\nIt was discovered that Roundcube Webmail did not properly treat an SVG\ntag as an image source within its HTML sanitizer. An attacker could possibly use\nthis issue to bypass remote image blocking to track email open actions or\npotentially bypass access control. (CVE-2026-25916)\n\nIt was discovered that Roundcube Webmail did not properly handle comments within\nCascading Style Sheets (CSS). An attacker could possibly use this issue to perform\na CSS injection attack. (CVE-2026-26079)","is_hidden":false,"release_packages":{"bionic":[{"name":"roundcube","version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","description":"skinnable AJAX based webmail solution for IMAP servers - metapackage","is_source":true},{"name":"roundcube","version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-core","version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-mysql","version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-pgsql","version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-plugins","version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-sqlite3","version":"1.3.6+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"roundcube","version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","description":"skinnable AJAX based webmail solution for IMAP servers - metapackage","is_source":true},{"name":"roundcube","version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-core","version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-mysql","version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-pgsql","version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-plugins","version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-sqlite3","version":"1.4.3+dfsg.1-1ubuntu0.1~esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"roundcube","version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","description":"skinnable AJAX based webmail solution for IMAP servers - metapackage","is_source":true},{"name":"roundcube","version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-core","version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-mysql","version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-pgsql","version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-plugins","version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-sqlite3","version":"1.5.0+dfsg.1-2ubuntu0.1~esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"roundcube","version":"1.6.6+dfsg-2ubuntu0.1+esm3","description":"skinnable AJAX based webmail solution for IMAP servers - metapackage","is_source":true},{"name":"roundcube","version":"1.6.6+dfsg-2ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-core","version":"1.6.6+dfsg-2ubuntu0.1+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-mysql","version":"1.6.6+dfsg-2ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-pgsql","version":"1.6.6+dfsg-2ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-plugins","version":"1.6.6+dfsg-2ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-sqlite3","version":"1.6.6+dfsg-2ubuntu0.1+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"roundcube","version":"1.2~beta+dfsg.1-0ubuntu1+esm8","description":"skinnable AJAX based webmail solution for IMAP servers - metapackage","is_source":true},{"name":"roundcube","version":"1.2~beta+dfsg.1-0ubuntu1+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-core","version":"1.2~beta+dfsg.1-0ubuntu1+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-mysql","version":"1.2~beta+dfsg.1-0ubuntu1+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-pgsql","version":"1.2~beta+dfsg.1-0ubuntu1+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-plugins","version":"1.2~beta+dfsg.1-0ubuntu1+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-sqlite3","version":"1.2~beta+dfsg.1-0ubuntu1+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2024-42010","CVE-2024-42008","CVE-2019-15237","CVE-2026-25916","CVE-2024-38357","CVE-2024-38356","CVE-2026-26079"]}]},{"id":"CVE-2025-15564","published":"2026-02-07T22:16:00","updated_at":"2026-09-11T06:58:48.216512+00:00","description":"\nA vulnerability has been found in Mapnik up to 4.2.0. This vulnerability\naffects the function mapnik::detail::mod<...>::operator of the file\nsrc/value.cpp. The manipulation leads to divide by zero. The attack needs\nto be performed locally. The exploit has been disclosed to the public and\nmay be used. The project was informed of the problem early through an issue\nreport but has not responded yet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-15564","https://github.com/mapnik/mapnik/issues/4545","https://github.com/mapnik/mapnik/","https://github.com/oneafter/1219/blob/main/repro","https://vuldb.com/?ctiid.344502","https://vuldb.com/?id.344502","https://vuldb.com/?submit.743386"],"bugs":[""],"patches":{"mapnik":[]},"tags":{},"packages":[{"name":"mapnik","source":"https://ubuntu.com/security/cve?package=mapnik","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mapnik","debian":"https://tracker.debian.org/pkg/mapnik","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25749","published":"2026-02-06T23:15:00","updated_at":"2026-03-18T05:12:03.606623+00:00","description":"\nVim is an open source, command line text editor. Prior to version 9.1.2132,\na heap buffer overflow vulnerability exists in Vim's tag file resolution\nlogic when processing the 'helpfile' option. The vulnerability is located\nin the get_tagfname() function in src/tag.c. When processing help file\ntags, Vim copies the user-controlled 'helpfile' option value into a\nfixed-size heap buffer of MAXPATHL + 1 bytes (typically 4097 bytes) using\nan unsafe STRCPY() operation without any bounds checking. This issue has\nbeen patched in version 9.1.2132.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nInput that can cause a buffer overflow is supplied by the user"}],"codename":null,"priority":"low","cvss3":6.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25749","https://github.com/vim/vim/security/advisories/GHSA-5w93-4g67-mm43","https://github.com/vim/vim/releases/tag/v9.1.2132","https://ubuntu.com/security/notices/USN-8101-1"],"bugs":[""],"patches":{"vim":["upstream: https://github.com/vim/vim/commit/0714b15940b245108e6e9d7aa2260dd849a26fa9"]},"tags":{},"packages":[{"name":"vim","source":"https://ubuntu.com/security/cve?package=vim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=vim","debian":"https://tracker.debian.org/pkg/vim","statuses":[{"release_codename":"upstream","status":"released","description":"9.1.2132","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"2:9.1.0967-1ubuntu6.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2:8.0.1453-1ubuntu1.13+esm14","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"2:8.1.2269-1ubuntu5.32+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"2:8.2.3995-1ubuntu2.26","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"2:9.1.0016-1ubuntu7.10","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:7.4.052-1ubuntu3.1+esm23","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"2:7.4.1689-3ubuntu1.5+esm29","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-8101-1"],"notices":[{"id":"USN-8101-1","title":"Vim vulnerabilities","summary":"Several security issues were fixed in Vim.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-03-16T22:15:39.936524","description":"Rahul Hoysala discovered that Vim did not correctly handle certain tag\nresolutions. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-25749)\n\nIt was discovered that Vim did not correctly handle processing certain\nspecialKey commands. An attacker could possibly use this issue to cause a\ndenial of service or execute arbitrary code. (CVE-2026-26269)\n\nKim Dong Han discovered that Vim did not correctly handle opening certain\nURLs. If a user or system were tricked into opening a specially crafted\nfile, an attacker could possibly use this issue to execute arbitrary code.\n(CVE-2026-28417)\n\nKim Dong Han discovered that Vim did not correctly handle parsing\nEmacs-style tag files. An attacker could possibly use this issue to cause\na denial of service. (CVE-2026-28418, CVE-2026-28419)\n\nKim Dong Han discovered that Vim did not correctly handle processing\nmaximum combining characters from Unicode supplementary planes. An attacker\ncould possibly use this issue to cause a denial of service or execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10.\n(CVE-2026-28420)\n\nKim Dong Han discovered that Vim did not correctly handle swap file\nrecovery. An attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. (CVE-2026-28421)\n\nKim Dong Han discovered that Vim did not correctly handle rendering\nstatus lines. An attacker could possibly use this issue to cause a denial\nof service or execute arbitrary code. (CVE-2026-28422)","is_hidden":false,"release_packages":{"bionic":[{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm14","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"xxd","version":"2:8.0.1453-1ubuntu1.13+esm14","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"vim","version":"2:8.1.2269-1ubuntu5.32+esm2","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"xxd","version":"2:8.1.2269-1ubuntu5.32+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"vim","version":"2:8.2.3995-1ubuntu2.26","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"vim-athena","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"vim-common","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"vim-doc","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"vim-gtk","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"vim-gtk3","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"vim-gui-common","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"vim-nox","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"vim-runtime","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"vim-tiny","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"},{"name":"xxd","version":"2:8.2.3995-1ubuntu2.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:8.2.3995-1ubuntu2.26","pocket":"security"}],"noble":[{"name":"vim","version":"2:9.1.0016-1ubuntu7.10","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"vim-athena","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"vim-common","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"vim-doc","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"vim-gtk3","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"vim-gui-common","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"vim-motif","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"vim-nox","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"vim-runtime","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"vim-tiny","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"},{"name":"xxd","version":"2:9.1.0016-1ubuntu7.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0016-1ubuntu7.10","pocket":"security"}],"questing":[{"name":"vim","version":"2:9.1.0967-1ubuntu6.1","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"vim-athena","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"vim-common","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"vim-doc","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"vim-gtk3","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"vim-gui-common","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"vim-motif","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"vim-nox","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"vim-runtime","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"vim-tiny","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"},{"name":"xxd","version":"2:9.1.0967-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":"https://launchpad.net/ubuntu/+source/vim/2:9.1.0967-1ubuntu6.1","pocket":"security"}],"trusty":[{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm23","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-athena","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-common","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-doc","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-gnome","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-gtk","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-gui-common","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-lesstif","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-nox","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-runtime","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"},{"name":"vim-tiny","version":"2:7.4.052-1ubuntu3.1+esm23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"vim","version":"2:7.4.1689-3ubuntu1.5+esm29","description":"Vi IMproved - enhanced vi editor","is_source":true},{"name":"vim","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-athena-py2","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-common","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-doc","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gnome-py2","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk-py2","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gtk3-py2","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-gui-common","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-nox-py2","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-runtime","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"},{"name":"vim-tiny","version":"2:7.4.1689-3ubuntu1.5+esm29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/vim","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2026-25749","CVE-2026-28421","CVE-2026-28422","CVE-2026-28418","CVE-2026-28417","CVE-2026-28420","CVE-2026-26269","CVE-2026-28419"]}]},{"id":"CVE-2026-2069","published":"2026-02-06T22:16:00","updated_at":"2026-09-11T06:56:45.107906+00:00","description":"\nA flaw has been found in ggml-org llama.cpp up to 55abc39. Impacted is the\nfunction llama_grammar_advance_stack of the file\nllama.cpp/src/llama-grammar.cpp of the component GBNF Grammar Handler. This\nmanipulation causes stack-based buffer overflow. The attack needs to be\nlaunched locally. The exploit has been published and may be used. Patch\nname: 18993. To fix this issue, it is recommended to deploy a patch.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-2069","https://github.com/ggml-org/llama.cpp/","https://github.com/ggml-org/llama.cpp/issues/18988","https://github.com/ggml-org/llama.cpp/issues/18988#event-4426704865","https://github.com/ggml-org/llama.cpp/pull/18993","https://github.com/user-attachments/files/24761101/poc.zip","https://vuldb.com/?ctiid.344636","https://vuldb.com/?id.344636","https://vuldb.com/?submit.745263"],"bugs":[""],"patches":{"llama.cpp":[]},"tags":{},"packages":[{"name":"llama.cpp","source":"https://ubuntu.com/security/cve?package=llama.cpp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=llama.cpp","debian":"https://tracker.debian.org/pkg/llama.cpp","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25731","published":"2026-02-06T21:16:00","updated_at":"2026-02-11T03:38:53.339165+00:00","description":"\ncalibre is an e-book manager. Prior to 9.2.0, a Server-Side Template\nInjection (SSTI) vulnerability in Calibre's Templite templating engine\nallows arbitrary code execution when a user converts an ebook using a\nmalicious custom template file via the --template-html or\n--template-html-index command-line options. This vulnerability is fixed in\n9.2.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25731","https://github.com/kovidgoyal/calibre/commit/f0649b27512e987b95fcab2e1e0a3bcdafc23379","https://github.com/kovidgoyal/calibre/security/advisories/GHSA-xrh9-w7qx-3gcc"],"bugs":[""],"patches":{"calibre":[]},"tags":{},"packages":[{"name":"calibre","source":"https://ubuntu.com/security/cve?package=calibre","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=calibre","debian":"https://tracker.debian.org/pkg/calibre","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25636","published":"2026-02-06T21:16:00","updated_at":"2026-02-11T03:36:06.988117+00:00","description":"\ncalibre is an e-book manager. In 9.1.0 and earlier, a path traversal\nvulnerability in Calibre's EPUB conversion allows a malicious EPUB file to\ncorrupt arbitrary existing files writable by the Calibre process. During\nconversion, Calibre resolves CipherReference URI from\nMETA-INF/encryption.xml to an absolute filesystem path and opens it in\nread-write mode, even when it points outside the conversion extraction\ndirectory. This vulnerability is fixed in 9.2.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25636","https://github.com/kovidgoyal/calibre/commit/9484ea82c6ab226c18e6ca5aa000fa16de598726","https://github.com/kovidgoyal/calibre/security/advisories/GHSA-8r26-m7j5-hm29"],"bugs":[""],"patches":{"calibre":[]},"tags":{},"packages":[{"name":"calibre","source":"https://ubuntu.com/security/cve?package=calibre","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=calibre","debian":"https://tracker.debian.org/pkg/calibre","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25635","published":"2026-02-06T21:16:00","updated_at":"2026-02-11T03:35:19.744243+00:00","description":"\ncalibre is an e-book manager. Prior to 9.2.0, Calibre's CHM reader contains\na path traversal vulnerability that allows arbitrary file writes anywhere\nthe user has write permissions. On Windows (haven't tested on other OS's),\nthis can lead to Remote Code Execution by writing a payload to the Startup\nfolder, which executes on next login. This vulnerability is fixed in 9.2.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25635","https://github.com/kovidgoyal/calibre/commit/9739232fcb029ac15dfe52ccd4fdb4a07ebb6ce9","https://github.com/kovidgoyal/calibre/security/advisories/GHSA-32vh-whvh-9fxr"],"bugs":[""],"patches":{"calibre":[]},"tags":{},"packages":[{"name":"calibre","source":"https://ubuntu.com/security/cve?package=calibre","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=calibre","debian":"https://tracker.debian.org/pkg/calibre","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25727","published":"2026-02-06T20:16:00","updated_at":"2026-07-10T19:45:54.306832+00:00","description":"\ntime provides date and time handling in Rust. From 0.3.6 to before 0.3.47,\nwhen user-provided input is provided to any type that parses with the RFC\n2822 format, a denial of service attack via stack exhaustion is possible.\nThe attack relies on formally deprecated and rarely-used features that are\npart of the RFC 2822 format used in a malicious manner. Ordinary,\nnon-malicious input will never encounter this scenario. A limit to the\ndepth of recursion was added in v0.3.47. From this version, an error will\nbe returned rather than exhausting the stack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},"baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25727","https://rustsec.org/advisories/RUSTSEC-2026-0009.html","https://github.com/advisories/GHSA-r6v5-fh4h-64xc","https://github.com/time-rs/time/blob/main/CHANGELOG.md#0347-2026-02-05","https://github.com/time-rs/time/commit/1c63dc7985b8fa26bd8c689423cc56b7a03841ee","https://github.com/time-rs/time/releases/tag/v0.3.47","https://github.com/time-rs/time/security/advisories/GHSA-r6v5-fh4h-64xc"],"bugs":[""],"patches":{"rust-time":[]},"tags":{},"packages":[{"name":"rust-time","source":"https://ubuntu.com/security/cve?package=rust-time","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-time","debian":"https://tracker.debian.org/pkg/rust-time","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.3.47-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-1709","published":"2026-02-06T20:16:00","updated_at":"2026-02-11T03:37:26.214048+00:00","description":"\nA flaw was found in Keylime. The Keylime registrar, since version 7.12.0,\ndoes not enforce client-side Transport Layer Security (TLS) authentication.\nThis authentication bypass vulnerability allows unauthenticated clients\nwith network access to perform administrative operations, including listing\nagents, retrieving public Trusted Platform Module (TPM) data, and deleting\nagents, by connecting without presenting a client certificate.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-1709","https://access.redhat.com/security/cve/CVE-2026-1709","https://bugzilla.redhat.com/show_bug.cgi?id=2435514"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-25556","published":"2026-02-06T17:16:00","updated_at":"2026-07-10T19:45:54.306832+00:00","description":"\nMuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in\nfz_fill_pixmap_from_display_list() when an exception occurs during display\nlist rendering. The function accepts a caller-owned fz_pixmap pointer but\nincorrectly drops the pixmap in its error handling path before rethrowing\nthe exception. Callers (including the barcode decoding path in\nfz_decode_barcode_from_display_list) also drop the same pixmap in cleanup,\nresulting in a double-free that can corrupt the heap and crash the process.\nThis issue affects applications that enable and use MuPDF barcode decoding\nand can be triggered by processing crafted input that causes a\nrendering-time error while decoding barcodes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-25556","https://bugs.ghostscript.com/show_bug.cgi?id=709029","https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=d4743b6092d513321c23c6f7fe5cff87cde043c1","https://mupdf.com/","https://www.vulncheck.com/advisories/mupdf-barcode-decoding-double-free"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1127318"],"patches":{"mupdf":[]},"tags":{},"packages":[{"name":"mupdf","source":"https://ubuntu.com/security/cve?package=mupdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mupdf","debian":"https://tracker.debian.org/pkg/mupdf","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-23741","published":"2026-02-06T17:16:00","updated_at":"2026-02-11T03:38:46.491257+00:00","description":"\nAsterisk is an open source private branch exchange and telephony toolkit.\nPrior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the\nasterisk/contrib/scripts/ast_coredumper runs as root, as noted by the NOTES\ntag on line 689 of the ast_coredumper file. The script will source the\ncontents of /etc/asterisk/ast_debug_tools.conf, which resides in a folder\nthat is writeable by the asterisk user:group. Due to the\n/etc/asterisk/ast_debug_tools.conf file following bash semantics and it\nbeing loaded; an attacker with write permissions may add or modify the file\nsuch that when the root ast_coredumper is run; it would source and thereby\nexecute arbitrary bash code found in the\n/etc/asterisk/ast_debug_tools.conf. This issue has been patched in versions\n20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":0.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":0.0,"baseSeverity":"NONE"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23741","https://github.com/asterisk/asterisk/security/advisories/GHSA-rvch-3jmx-3jf3"],"bugs":[""],"patches":{"asterisk":[]},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-23740","published":"2026-02-06T17:16:00","updated_at":"2026-02-11T03:36:54.263363+00:00","description":"\nAsterisk is an open source private branch exchange and telephony toolkit.\nPrior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, when\nast_coredumper writes its gdb init and output files to a directory that is\nworld-writable (for example /tmp), an attacker with write permission(which\nis all users on a linux system) to that directory can cause root to execute\narbitrary commands or overwrite arbitrary files by controlling the gdb init\nfile and output paths. This issue has been patched in versions 20.7-cert9,\n20.18.2, 21.12.1, 22.8.2, and 23.2.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":0.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":0.0,"baseSeverity":"NONE"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23740","https://github.com/asterisk/asterisk/security/advisories/GHSA-xpc6-x892-v83c"],"bugs":[""],"patches":{"asterisk":[]},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-23739","published":"2026-02-06T17:16:00","updated_at":"2026-02-11T03:39:19.544674+00:00","description":"\nAsterisk is an open source private branch exchange and telephony toolkit.\nPrior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the\nast_xml_open() function in xml.c parses XML documents using libxml with\nunsafe parsing options that enable entity expansion and XInclude\nprocessing. Specifically, it invokes xmlReadFile() with the XML_PARSE_NOENT\nflag and later processes XIncludes via xmlXIncludeProcess().If any\nuntrusted or user-supplied XML file is passed to this function, it can\nallow an attacker to trigger XML External Entity (XXE) or XInclude-based\nlocal file disclosure, potentially exposing sensitive files from the host\nsystem. This can also be triggered in other cases in which the user is able\nto supply input in xml format that triggers the asterisk process to parse\nit. This issue has been patched in versions 20.7-cert9, 20.18.2, 21.12.1,\n22.8.2, and 23.2.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":2.0,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-23739","https://github.com/asterisk/asterisk/security/advisories/GHSA-85x7-54wr-vh42"],"bugs":[""],"patches":{"asterisk":[]},"tags":{},"packages":[{"name":"asterisk","source":"https://ubuntu.com/security/cve?package=asterisk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=asterisk","debian":"https://tracker.debian.org/pkg/asterisk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":15560,"limit":20,"total_results":79316}