{"cves":[{"id":"CVE-2025-47914","published":"2025-11-19T21:15:00","updated_at":"2026-01-12T10:21:46.804613+00:00","description":"\nSSH Agent servers do not validate the size of messages when processing new\nidentity requests, which may cause the program to panic if the message is\nmalformed due to an out of bounds read.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"snapd contains an embedded copy of golang-go.crypto\nlxd in 18.04 LTS and earlier contains an embedded copy of\ngolang-go.crypto"},{"author":"hlibk","note":"google-guest-agent contains an embedded copy of golang-go.crypto"},{"author":"0xnishit","note":"google-guest-agent doesnt vendor ssh/agent code"}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-47914","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA?pli=1","https://github.com/golang/go/issues/76364","https://go.dev/cl/721960","https://go.dev/issue/76364","https://groups.google.com/g/golang-announce/c/w-oX3UxNcZA","https://pkg.go.dev/vuln/GO-2025-4135","https://github.com/golang/crypto/commit/f91f7a7c31bf90b39c1de895ad116a2bacc88748"],"bugs":[""],"patches":{"golang-go.crypto":[],"snapd":[],"lxd":[],"google-guest-agent":[]},"tags":{},"packages":[{"name":"golang-go.crypto","source":"https://ubuntu.com/security/cve?package=golang-go.crypto","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-go.crypto","debian":"https://tracker.debian.org/pkg/golang-go.crypto","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"snapd","source":"https://ubuntu.com/security/cve?package=snapd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=snapd","debian":"https://tracker.debian.org/pkg/snapd","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"google-guest-agent","source":"https://ubuntu.com/security/cve?package=google-guest-agent","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=google-guest-agent","debian":"https://tracker.debian.org/pkg/google-guest-agent","statuses":[{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"lxd","source":"https://ubuntu.com/security/cve?package=lxd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lxd","debian":"https://tracker.debian.org/pkg/lxd","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code-not-present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-13086","published":"2025-11-19T00:00:00","updated_at":"2025-12-17T07:02:48.502436+00:00","description":"\nImproper validation of source IP addresses in OpenVPN version 2.6.0 through\n2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session\nfrom a different IP address which did not initiate the connection resulting\nin a denial of service for the originating client","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This only affects 2.6.0 through 2.6.15"}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-13086","https://community.openvpn.net/Security%20Announcements/CVE-2025-13086","https://ubuntu.com/security/notices/USN-7898-1"],"bugs":[""],"patches":{"openvpn":["upstream: https://github.com/OpenVPN/openvpn/commit/fa6a1824b0f37bff137204156a74ca28cf5b6f83"]},"tags":{},"packages":[{"name":"openvpn","source":"https://ubuntu.com/security/cve?package=openvpn","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openvpn","debian":"https://tracker.debian.org/pkg/openvpn","statuses":[{"release_codename":"noble","status":"released","description":"2.6.14-0ubuntu0.24.04.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"2.6.14-0ubuntu0.25.04.3","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"2.6.14-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.5.11-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.0,2.6.16,2.7.0~rc2-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-7898-1"],"notices":[{"id":"USN-7898-1","title":"OpenVPN vulnerability","summary":"OpenVPN could allow unintended access to network services.","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.","references":[],"published":"2025-11-27T16:34:52.543458","description":"Joshua Rogers discovered that OpenVPN incorrectly handled HMAC verification\nchecks. A remote attacker could possibly use this issue to bypass source IP\naddress validation.","is_hidden":false,"release_packages":{"noble":[{"name":"openvpn","version":"2.6.14-0ubuntu0.24.04.3","description":"virtual private network software","is_source":true},{"name":"openvpn","version":"2.6.14-0ubuntu0.24.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvpn","version_link":"https://launchpad.net/ubuntu/+source/openvpn/2.6.14-0ubuntu0.24.04.3","pocket":"security"}],"plucky":[{"name":"openvpn","version":"2.6.14-0ubuntu0.25.04.3","description":"virtual private network software","is_source":true},{"name":"openvpn","version":"2.6.14-0ubuntu0.25.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvpn","version_link":"https://launchpad.net/ubuntu/+source/openvpn/2.6.14-0ubuntu0.25.04.3","pocket":"security"}],"questing":[{"name":"openvpn","version":"2.6.14-2ubuntu1.1","description":"virtual private network software","is_source":true},{"name":"openvpn","version":"2.6.14-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvpn","version_link":"https://launchpad.net/ubuntu/+source/openvpn/2.6.14-2ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-13086"]}]},{"id":"CVE-2025-65015","published":"2025-11-18T23:15:00","updated_at":"2026-07-10T19:13:50.335658+00:00","description":"\njoserfc is a Python library that provides an implementation of several JSON\nObject Signing and Encryption (JOSE) standards. In versions from 1.3.3 to\nbefore 1.3.5 and from 1.4.0 to before 1.4.2, the ExceededSizeError\nexception messages are embedded with non-decoded JWT token parts and may\ncause Python logging to record an arbitrarily large, forged JWT payload. In\nsituations where a misconfigured — or entirely absent — production-grade\nweb server sits in front of a Python web application, an attacker may be\nable to send arbitrarily large bearer tokens in the HTTP request headers.\nWhen this occurs, Python logging or diagnostic tools (e.g., Sentry) may end\nup processing extremely large log messages containing the full JWT header\nduring the joserfc.jwt.decode() operation. The same behavior also appears\nwhen validating claims and signature payload sizes, as the library raises\njoserfc.errors.ExceededSizeError() with the full payload embedded in the\nexception message. Since the payload is already fully loaded into memory at\nthis stage, the library cannot prevent or reject it. This issue has been\npatched in versions 1.3.5 and 1.4.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},"baseScore":9.2,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-65015","https://github.com/authlib/joserfc/security/advisories/GHSA-frfh-8v73-gjg4","https://github.com/authlib/joserfc/commit/63932f169d924caffafa761af2122b82059017f7","https://github.com/authlib/joserfc/commit/673c8743fd0605b0e1de6452be6cba75f44e466b","https://github.com/authlib/joserfc/releases/tag/1.3.5","https://github.com/authlib/joserfc/releases/tag/1.4.2"],"bugs":[""],"patches":{"joserfc":[]},"tags":{},"packages":[{"name":"joserfc","source":"https://ubuntu.com/security/cve?package=joserfc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=joserfc","debian":"https://tracker.debian.org/pkg/joserfc","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-12119","published":"2025-11-18T22:15:00","updated_at":"2026-07-10T07:18:08.605724+00:00","description":"\nA mongoc_bulk_operation_t may read invalid memory if large options are\npassed.","ubuntu_description":"","notes":[{"author":"rodrigo-zaiden","note":"php-mongodb bundles libmongoc library, which was updated\nwith the fix for this CVE."}],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.8,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-12119","https://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6","https://github.com/mongodb/mongo-c-driver/releases/tag/2.1.2","https://github.com/mongodb/mongo-php-driver/releases/tag/1.21.2"],"bugs":["https://jira.mongodb.org/browse/CDRIVER-6112 (private)"],"patches":{"mongo-c-driver":["upstream: https://github.com/mongodb/mongo-c-driver/commit/200d0f8129a0d06f5b300cccef045cff5e72b4fb"],"php-mongodb":[]},"tags":{},"packages":[{"name":"mongo-c-driver","source":"https://ubuntu.com/security/cve?package=mongo-c-driver","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongo-c-driver","debian":"https://tracker.debian.org/pkg/mongo-c-driver","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.1.2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"php-mongodb","source":"https://ubuntu.com/security/cve?package=php-mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-mongodb","debian":"https://tracker.debian.org/pkg/php-mongodb","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-61664","published":"2025-11-18T19:15:00","updated_at":"2025-11-19T15:19:32.030699+00:00","description":"\nA vulnerability in the GRUB2 bootloader has been identified in the normal\nmodule. This flaw, a memory Use After Free issue, occurs because the\nnormal_exit command is not properly unregistered when its related module is\nunloaded. An attacker can exploit this condition by invoking the command\nafter the module has been removed, causing the system to improperly access\na previously freed memory location. This leads to a system crash or\npossible impacts in data confidentiality and integrity.","ubuntu_description":"","notes":[{"author":"eslerm","note":"the grub2 package does not affect Ubuntu's Secure Boot\ngrub2-unsigned contains Secure Boot security fixes grub2 and\ngrub2-unsigned should have same major version Ubuntu Secure Boot\nand ESM do not cover i386 trusty's GA kernel cannot handle new\nversions of grub Note that key revocation is required to protect\nagainst evil housekeeper attacks (such as BlackLotus)"}],"codename":null,"priority":"medium","cvss3":4.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-61664","https://access.redhat.com/security/cve/CVE-2025-61664"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1120968","https://bugzilla.redhat.com/show_bug.cgi?id=2414685"],"patches":{"grub2":["upstream: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=05d3698b8b03eccc49e53491bbd75dba15f40917"],"grub2-unsigned":[],"grub2-signed":[]},"tags":{},"packages":[{"name":"grub2-unsigned","source":"https://ubuntu.com/security/cve?package=grub2-unsigned","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-unsigned","debian":"https://tracker.debian.org/pkg/grub2-unsigned","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"grub2-signed","source":"https://ubuntu.com/security/cve?package=grub2-signed","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-signed","debian":"https://tracker.debian.org/pkg/grub2-signed","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"grub2","source":"https://ubuntu.com/security/cve?package=grub2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2","debian":"https://tracker.debian.org/pkg/grub2","statuses":[{"release_codename":"resolute","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-61663","published":"2025-11-18T19:15:00","updated_at":"2025-11-19T15:21:26.347586+00:00","description":"\nA vulnerability has been identified in the GRUB2 bootloader's normal\ncommand that poses an immediate Denial of Service (DoS) risk. This flaw is\na Use-after-Free issue, caused because the normal command is not properly\nunregistered when the module is unloaded. An attacker who can execute this\ncommand can force the system to access memory locations that are no longer\nvalid. Successful exploitation leads directly to system instability, which\ncan result in a complete crash and halt system availability. Impact on the\ndata integrity and confidentiality is also not discarded.","ubuntu_description":"","notes":[{"author":"eslerm","note":"the grub2 package does not affect Ubuntu's Secure Boot\ngrub2-unsigned contains Secure Boot security fixes grub2 and\ngrub2-unsigned should have same major version Ubuntu Secure Boot\nand ESM do not cover i386 trusty's GA kernel cannot handle new\nversions of grub Note that key revocation is required to protect\nagainst evil housekeeper attacks (such as BlackLotus)"}],"codename":null,"priority":"medium","cvss3":4.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-61663","https://access.redhat.com/security/cve/CVE-2025-61663"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1120968","https://bugzilla.redhat.com/show_bug.cgi?id=2414684"],"patches":{"grub2":["upstream: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=05d3698b8b03eccc49e53491bbd75dba15f40917"],"grub2-unsigned":[],"grub2-signed":[]},"tags":{},"packages":[{"name":"grub2-unsigned","source":"https://ubuntu.com/security/cve?package=grub2-unsigned","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-unsigned","debian":"https://tracker.debian.org/pkg/grub2-unsigned","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"grub2-signed","source":"https://ubuntu.com/security/cve?package=grub2-signed","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-signed","debian":"https://tracker.debian.org/pkg/grub2-signed","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"grub2","source":"https://ubuntu.com/security/cve?package=grub2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2","debian":"https://tracker.debian.org/pkg/grub2","statuses":[{"release_codename":"resolute","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-61662","published":"2025-11-18T19:15:00","updated_at":"2026-01-23T13:23:25.145633+00:00","description":"\nA Use-After-Free vulnerability has been discovered in GRUB's gettext\nmodule. This flaw stems from a programming error where the gettext command\nremains registered in memory after its module is unloaded. An attacker can\nexploit this condition by invoking the orphaned command, causing the\napplication to access a memory location that is no longer valid. An\nattacker could exploit this vulnerability to cause grub to crash, leading\nto a Denial of Service. Possible data integrity or confidentiality\ncompromise is not discarded.","ubuntu_description":"","notes":[{"author":"eslerm","note":"the grub2 package does not affect Ubuntu's Secure Boot\ngrub2-unsigned contains Secure Boot security fixes grub2 and\ngrub2-unsigned should have same major version Ubuntu Secure Boot\nand ESM do not cover i386 trusty's GA kernel cannot handle new\nversions of grub Note that key revocation is required to protect\nagainst evil housekeeper attacks (such as BlackLotus)"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-61662","https://access.redhat.com/security/cve/CVE-2025-61662","http://www.openwall.com/lists/oss-security/2025/11/18/5"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1120968","https://bugzilla.redhat.com/show_bug.cgi?id=2414683"],"patches":{"grub2":["upstream: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=8ed78fd9f0852ab218cc1f991c38e5a229e43807"],"grub2-unsigned":[],"grub2-signed":[]},"tags":{},"packages":[{"name":"grub2-unsigned","source":"https://ubuntu.com/security/cve?package=grub2-unsigned","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-unsigned","debian":"https://tracker.debian.org/pkg/grub2-unsigned","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"grub2-signed","source":"https://ubuntu.com/security/cve?package=grub2-signed","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-signed","debian":"https://tracker.debian.org/pkg/grub2-signed","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"grub2","source":"https://ubuntu.com/security/cve?package=grub2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2","debian":"https://tracker.debian.org/pkg/grub2","statuses":[{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-61661","published":"2025-11-18T19:15:00","updated_at":"2025-11-19T15:22:06.825513+00:00","description":"\nA vulnerability has been identified in the GRUB (Grand Unified Bootloader)\ncomponent. This flaw occurs because the bootloader mishandles string\nconversion when reading information from a USB device, allowing an attacker\nto exploit inconsistent length values. A local attacker can connect a\nmaliciously configured USB device during the boot sequence to trigger this\nissue. A successful exploitation may lead GRUB to crash, leading to a\nDenial of Service. Data corruption may be also possible, although given the\ncomplexity of the exploit the impact is most likely limited.","ubuntu_description":"","notes":[{"author":"eslerm","note":"the grub2 package does not affect Ubuntu's Secure Boot\ngrub2-unsigned contains Secure Boot security fixes grub2 and\ngrub2-unsigned should have same major version Ubuntu Secure Boot\nand ESM do not cover i386 trusty's GA kernel cannot handle new\nversions of grub Note that key revocation is required to protect\nagainst evil housekeeper attacks (such as BlackLotus)"}],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H","attackVector":"PHYSICAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-61661","https://access.redhat.com/security/cve/CVE-2025-61661","http://www.openwall.com/lists/oss-security/2025/11/18/8"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1120968","https://bugzilla.redhat.com/show_bug.cgi?id=2413827"],"patches":{"grub2":["upstream: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=549a9cc372fd0b96a4ccdfad0e12140476cc62a3"],"grub2-unsigned":[],"grub2-signed":[]},"tags":{},"packages":[{"name":"grub2-unsigned","source":"https://ubuntu.com/security/cve?package=grub2-unsigned","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-unsigned","debian":"https://tracker.debian.org/pkg/grub2-unsigned","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"grub2-signed","source":"https://ubuntu.com/security/cve?package=grub2-signed","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-signed","debian":"https://tracker.debian.org/pkg/grub2-signed","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"grub2","source":"https://ubuntu.com/security/cve?package=grub2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2","debian":"https://tracker.debian.org/pkg/grub2","statuses":[{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-54771","published":"2025-11-18T19:15:00","updated_at":"2025-11-19T15:20:30.989916+00:00","description":"\nA use-after-free vulnerability has been identified in the GNU GRUB (Grand\nUnified Bootloader). The flaw occurs because the file-closing process\nincorrectly retains a memory pointer, leaving an invalid reference to a\nfile system structure. An attacker could exploit this vulnerability to\ncause grub to crash, leading to a Denial of Service. Possible data\nintegrity or confidentiality compromise is not discarded.","ubuntu_description":"","notes":[{"author":"eslerm","note":"the grub2 package does not affect Ubuntu's Secure Boot\ngrub2-unsigned contains Secure Boot security fixes grub2 and\ngrub2-unsigned should have same major version Ubuntu Secure Boot\nand ESM do not cover i386 trusty's GA kernel cannot handle new\nversions of grub Note that key revocation is required to protect\nagainst evil housekeeper attacks (such as BlackLotus)"}],"codename":null,"priority":"medium","cvss3":4.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-54771","https://access.redhat.com/security/cve/CVE-2025-54771","http://www.openwall.com/lists/oss-security/2025/11/18/3"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1120968","https://bugzilla.redhat.com/show_bug.cgi?id=2413823"],"patches":{"grub2":["upstream: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=c4fb4cbc941981894a00ba8e75d634a41967a27f"],"grub2-unsigned":[],"grub2-signed":[]},"tags":{},"packages":[{"name":"grub2-unsigned","source":"https://ubuntu.com/security/cve?package=grub2-unsigned","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-unsigned","debian":"https://tracker.debian.org/pkg/grub2-unsigned","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"grub2-signed","source":"https://ubuntu.com/security/cve?package=grub2-signed","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-signed","debian":"https://tracker.debian.org/pkg/grub2-signed","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"grub2","source":"https://ubuntu.com/security/cve?package=grub2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2","debian":"https://tracker.debian.org/pkg/grub2","statuses":[{"release_codename":"resolute","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-54770","published":"2025-11-18T19:15:00","updated_at":"2025-11-19T15:22:54.786970+00:00","description":"\nA vulnerability has been identified in the GRUB2 bootloader's network\nmodule that poses an immediate Denial of Service (DoS) risk. This flaw is a\nUse-after-Free issue, caused because the net_set_vlan command is not\nproperly unregistered when the network module is unloaded from memory. An\nattacker who can execute this command can force the system to access memory\nlocations that are no longer valid. Successful exploitation leads directly\nto system instability, which can result in a complete crash and halt system\navailability","ubuntu_description":"","notes":[{"author":"eslerm","note":"the grub2 package does not affect Ubuntu's Secure Boot\ngrub2-unsigned contains Secure Boot security fixes grub2 and\ngrub2-unsigned should have same major version Ubuntu Secure Boot\nand ESM do not cover i386 trusty's GA kernel cannot handle new\nversions of grub Note that key revocation is required to protect\nagainst evil housekeeper attacks (such as BlackLotus)"}],"codename":null,"priority":"medium","cvss3":4.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-54770","https://access.redhat.com/security/cve/CVE-2025-54770","http://www.openwall.com/lists/oss-security/2025/11/18/4"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1120968","https://bugzilla.redhat.com/show_bug.cgi?id=2413813"],"patches":{"grub2":["upstream: https://gitweb.git.savannah.gnu.org/gitweb/?p=grub.git;a=commit;h=10e58a14db20e17d1b6a39abe38df01fef98e29d"],"grub2-unsigned":[],"grub2-signed":[]},"tags":{},"packages":[{"name":"grub2-unsigned","source":"https://ubuntu.com/security/cve?package=grub2-unsigned","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-unsigned","debian":"https://tracker.debian.org/pkg/grub2-unsigned","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"grub2-signed","source":"https://ubuntu.com/security/cve?package=grub2-signed","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2-signed","debian":"https://tracker.debian.org/pkg/grub2-signed","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"grub2","source":"https://ubuntu.com/security/cve?package=grub2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grub2","debian":"https://tracker.debian.org/pkg/grub2","statuses":[{"release_codename":"resolute","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"update incompatible with kernel","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"does not affect Secure Boot","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-64076","published":"2025-11-18T18:16:00","updated_at":"2025-11-19T15:22:02.344931+00:00","description":"\nMultiple vulnerabilities exist in cbor2 through version 5.7.0 in the\ndecode_definite_long_string() function of the C extension decoder\n(source/decoder.c): (1) Integer Underflow Leading to Out-of-Bounds Read\n(CWE-191, CWE-125): An incorrect variable reference and missing state reset\nin the chunk processing loop causes buffer_length to not be reset to zero\nafter UTF-8 character consumption. This results in subsequent chunk_length\ncalculations producing negative values (e.g., chunk_length = 65536 -\nbuffer_length), which are passed as signed integers to the read() method,\npotentially triggering unlimited read operations and resource exhaustion.\n(2) Memory Leak via Missing Reference Count Release (CWE-401): The main\nprocessing loop fails to release Python object references (Py_DECREF) for\nchunk objects allocated in each iteration. For CBOR strings longer than\n65536 bytes, this causes cumulative memory leaks proportional to the\npayload size, enabling memory exhaustion attacks through repeated\nprocessing of large CBOR payloads. Both vulnerabilities can be exploited\nremotely without authentication by sending specially-crafted CBOR data\ncontaining definite-length text strings with multi-byte UTF-8 characters\npositioned at 65536-byte chunk boundaries. Successful exploitation results\nin denial of service through process crashes (CBORDecodeEOF exceptions) or\nmemory exhaustion. The vulnerabilities affect all applications using\ncbor2's C extension to process untrusted CBOR data, including web APIs, IoT\ndata collectors, and message queue processors. Fixed in commit\n851473490281f82d82560b2368284ef33cf6e8f9 pushed with released version\n5.7.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-64076","https://github.com/agronholm/cbor2/pull/265","https://github.com/agronholm/cbor2/commit/2349197bea8ebd1bf57a68f4a6549d8fd7585e66 (5.7.1)","https://github.com/agronholm/cbor2/commit/851473490281f82d82560b2368284ef33cf6e8f9"],"bugs":["https://github.com/agronholm/cbor2/issues/264"],"patches":{"cbor2":["upstream: https://github.com/agronholm/cbor2/commit/2349197bea8ebd1bf57a68f4a6549d8fd7585e66"]},"tags":{},"packages":[{"name":"cbor2","source":"https://ubuntu.com/security/cve?package=cbor2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cbor2","debian":"https://tracker.debian.org/pkg/cbor2","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"5.7.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7.1-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-63829","published":"2025-11-18T17:16:00","updated_at":"2025-11-19T15:22:30.486578+00:00","description":"\neProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused\nby integer overflow in the Time_t:: fraction() function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-63829","https://github.com/lkloliver/poc/tree/main/CVE-2025-63829","https://gist.github.com/lkloliver/b00377bec754d4aa1dc731be210d5889","https://github.com/eProsima/Fast-DDS/blob/master/src/cpp/fastdds/core/Time_t.cpp#L67"],"bugs":[""],"patches":{"fastdds":[]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-64996","published":"2025-11-18T16:15:00","updated_at":"2026-08-17T19:07:23.211161+00:00","description":"\nIn Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0\nand older, the mk_inotify plugin creates world-readable and writable files,\nallowing any local user on the system to read the plugin's output and\nmanipulate it, potentially leading to unauthorized access to or\nmodification of monitoring data.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-64996","https://checkmk.com/werk/18570"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-58122","published":"2025-11-18T16:15:00","updated_at":"2026-08-17T19:10:05.816538+00:00","description":"\nInsufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16\nallows low-privileged users to modify notification parameters via the REST\nAPI, which could lead to unauthorized actions or information disclosure.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-58122","https://checkmk.com/werk/18982"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-58121","published":"2025-11-18T16:15:00","updated_at":"2026-08-17T19:09:22.954219+00:00","description":"\nInsufficient permission validation on multiple REST API endpoints in\nCheckmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows\nlow-privileged users to perform unauthorized actions or obtain sensitive\ninformation","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-58121","https://checkmk.com/werk/18983"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-10158","published":"2025-11-18T15:16:00","updated_at":"2026-06-19T11:09:49.768735+00:00","description":"\nA malicious client acting as the receiver of an rsync file transfer can\ntrigger an out of bounds read of a heap based buffer, via a negative array\nindex. The\nmalicious\nrsync client requires at least read access to the remote rsync module in\norder to trigger the issue.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nPer rsync developers, can't be leveraged into an exploit"}],"codename":null,"priority":"low","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-10158","https://attackerkb.com/assessments/fbacb2a6-d1cd-4011-bb3a-f06b1c8306b1","https://ubuntu.com/security/notices/USN-8283-1","https://ubuntu.com/security/notices/USN-8349-1","https://ubuntu.com/security/notices/USN-8349-2","https://ubuntu.com/security/notices/USN-8349-3"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1121442"],"patches":{"rsync":["upstream: https://github.com/RsyncProject/rsync/commit/797e17fc4a6f15e3b1756538a9f812b63942686f"]},"tags":{},"packages":[{"name":"rsync","source":"https://ubuntu.com/security/cve?package=rsync","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rsync","debian":"https://tracker.debian.org/pkg/rsync","statuses":[{"release_codename":"resolute","status":"released","description":"3.4.1+ds1-7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.4.1+ds1-7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.1.2-2.1ubuntu1.6+esm3","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"3.1.3-8ubuntu0.9+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"3.1.0-2ubuntu0.4+esm3","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"3.1.1-3ubuntu1.3+esm5","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"jammy","status":"released","description":"3.2.7-0ubuntu0.22.04.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.2.7-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.4.1+ds1-5ubuntu1.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-8283-1","USN-8349-1"],"notices":[{"id":"USN-8283-1","title":"rsync vulnerabilities","summary":"Several security issues were fixed in rsync.","instructions":"In general, a standard system update will make all the necessary\nchanges. After a standard system update you need to restart rsync\ndaemons if configured to make all the necessary changes.","references":[],"published":"2026-05-20T12:41:44.253842","description":"Calum Hutton discovered that rsync contained a heap-based out-of-bounds\nread when handling file transfers. A remote attacker with read access\nto an rsync server could possibly use this issue to cause a denial of\nservice. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,\nand Ubuntu 25.10. (CVE-2025-10158)\n\nBatuhan Sancak, Damien Neil, and Michael Stapelberg discovered that\nrsync daemons configured without chroot protection were exposed to a\nrace condition on parent path components. A local attacker with write\naccess to a module could possibly use this issue to overwrite files,\nobtain sensitive information, or escalate privileges.\n(CVE-2026-29518)\n\nIt was discovered that rsync did not properly validate a length value\nwhile sorting extended attributes. An attacker could possibly use this\nissue to cause a denial of service. (CVE-2026-41035)\n\nIt was discovered that rsync performed reverse-DNS lookups after\nchrooting in some daemon configurations. A remote attacker could\npossibly use this issue to bypass hostname-based access controls and\naccess network services. (CVE-2026-43617)\n\nOmar Elsayed discovered that rsync did not properly check for integer\noverflows while decoding compressed tokens. A remote attacker could\npossibly use this issue to obtain sensitive information.\n(CVE-2026-43618)\n\nAndrew Tridgell discovered that rsync did not fully fix a symlink race\ncondition in path-based system calls for daemons configured without\nchroot protection. A local attacker could possibly use this issue to\noverwrite files, obtain sensitive information, or escalate privileges.\n(CVE-2026-43619)\n\nPratham Gupta discovered that rsync did not properly validate an index\nwhile processing file lists. A remote attacker could possibly use this\nissue to cause rsync to crash, resulting in a denial of service.\n(CVE-2026-43620)\n\nMichal Ruprich discovered that rsync contained an off-by-one error\nwhile handling HTTP proxy responses. An attacker able to intercept network\ncommunications or a malicious proxy server could possibly use this issue to\ncause a denial of service. (CVE-2026-45232)","is_hidden":false,"release_packages":{"jammy":[{"name":"rsync","version":"3.2.7-0ubuntu0.22.04.6","description":"fast, versatile, remote (and local) file-copying tool","is_source":true},{"name":"rsync","version":"3.2.7-0ubuntu0.22.04.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/rsync","version_link":"https://launchpad.net/ubuntu/+source/rsync/3.2.7-0ubuntu0.22.04.6","pocket":"security"}],"noble":[{"name":"rsync","version":"3.2.7-1ubuntu1.4","description":"fast, versatile, remote (and local) file-copying tool","is_source":true},{"name":"rsync","version":"3.2.7-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/rsync","version_link":"https://launchpad.net/ubuntu/+source/rsync/3.2.7-1ubuntu1.4","pocket":"security"}],"questing":[{"name":"rsync","version":"3.4.1+ds1-5ubuntu1.2","description":"fast, versatile, remote (and local) file-copying tool","is_source":true},{"name":"rsync","version":"3.4.1+ds1-5ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/rsync","version_link":"https://launchpad.net/ubuntu/+source/rsync/3.4.1+ds1-5ubuntu1.2","pocket":"security"}],"resolute":[{"name":"rsync","version":"3.4.1+ds1-7ubuntu0.2","description":"fast, versatile, remote (and local) file-copying tool","is_source":true},{"name":"rsync","version":"3.4.1+ds1-7ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/rsync","version_link":"https://launchpad.net/ubuntu/+source/rsync/3.4.1+ds1-7ubuntu0.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-43620","CVE-2026-43618","CVE-2026-43617","CVE-2026-45232","CVE-2026-43619","CVE-2026-29518","CVE-2026-41035","CVE-2025-10158"]},{"id":"USN-8349-1","title":"rsync vulnerabilities","summary":"Several security issues were fixed in rsync.","instructions":"In general, a standard system update will make all the necessary changes.\nAfter a standard system update you need to restart rsync daemons if configured\nto make all the necessary changes.","references":[],"published":"2026-06-01T09:20:17.575487","description":"Calum Hutton discovered that rsync contained a heap-based out-of-bounds\nread when handling file transfers. A remote attacker with read access\nto an rsync server could possibly use this issue to cause a denial of\nservice. (CVE-2025-10158)\n\nBatuhan Sancak, Damien Neil, and Michael Stapelberg discovered that\nrsync daemons configured without chroot protection were exposed to a\nrace condition on parent path components. A local attacker with write\naccess to a module could possibly use this issue to overwrite files,\nobtain sensitive information, or escalate privileges.\n(CVE-2026-29518)\n\nIt was discovered that rsync did not properly validate a length value\nwhile sorting extended attributes. An attacker could possibly use this\nissue to cause a denial of service. (CVE-2026-41035)\n\nIt was discovered that rsync performed reverse-DNS lookups after\nchrooting in some daemon configurations. A remote attacker could\npossibly use this issue to bypass hostname-based access controls and\naccess network services. (CVE-2026-43617)\n\nOmar Elsayed discovered that rsync did not properly check for integer\noverflows while decoding compressed tokens. A remote attacker could\npossibly use this issue to obtain sensitive information.\n(CVE-2026-43618)\n\nAndrew Tridgell discovered that rsync did not fully fix a symlink race\ncondition in path-based system calls for daemons configured without\nchroot protection. A local attacker could possibly use this issue to\noverwrite files, obtain sensitive information, or escalate privileges.\n(CVE-2026-43619)\n\nPratham Gupta discovered that rsync did not properly validate an index\nwhile processing file lists. A remote attacker could possibly use this\nissue to cause rsync to crash, resulting in a denial of service.\n(CVE-2026-43620)\n\nMichal Ruprich discovered that rsync contained an off-by-one error\nwhile handling HTTP proxy responses. An attacker able to intercept network\ncommunications or a malicious proxy server could possibly use this issue to\ncause a denial of service. (CVE-2026-45232)","is_hidden":false,"release_packages":{"bionic":[{"name":"rsync","version":"3.1.2-2.1ubuntu1.6+esm3","description":"fast, versatile, remote (and local) file-copying tool","is_source":true},{"name":"rsync","version":"3.1.2-2.1ubuntu1.6+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/rsync","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"rsync","version":"3.1.3-8ubuntu0.9+esm1","description":"fast, versatile, remote (and local) file-copying tool","is_source":true},{"name":"rsync","version":"3.1.3-8ubuntu0.9+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/rsync","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"rsync","version":"3.1.0-2ubuntu0.4+esm3","description":"fast, versatile, remote (and local) file-copying tool","is_source":true},{"name":"rsync","version":"3.1.0-2ubuntu0.4+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/rsync","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"rsync","version":"3.1.1-3ubuntu1.3+esm5","description":"fast, versatile, remote (and local) file-copying tool","is_source":true},{"name":"rsync","version":"3.1.1-3ubuntu1.3+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/rsync","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-43618","CVE-2025-10158","CVE-2026-41035","CVE-2026-43617","CVE-2026-43620","CVE-2026-43619","CVE-2026-29518","CVE-2026-45232"]}]},{"id":"CVE-2025-13230","published":"2025-11-18T00:00:00","updated_at":"2025-11-18T17:04:17.660011+00:00","description":"\nType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-13230","https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html","https://issues.chromium.org/issues/446124892"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-13229","published":"2025-11-18T00:00:00","updated_at":"2025-11-18T17:16:55.738611+00:00","description":"\nType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-13229","https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html","https://issues.chromium.org/issues/446113731"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-13228","published":"2025-11-18T00:00:00","updated_at":"2025-11-18T17:14:05.972667+00:00","description":"\nType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-13228","https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html","https://issues.chromium.org/issues/446124893"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-13227","published":"2025-11-18T00:00:00","updated_at":"2025-11-18T17:20:37.139363+00:00","description":"\nType Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-13227","https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop_28.html","https://issues.chromium.org/issues/446122633"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":17800,"limit":20,"total_results":79316}