{"cves":[{"id":"CVE-2026-80229","published":"2026-09-06T18:17:00","updated_at":"2026-09-16T10:45:15.564803+00:00","description":"\nWhen performing transfers via libcurl’s multi interface, pooled TLS\nconnections can outlive their originating easy handles. In OpenSSL 3\nprovider\nconfigurations, libcurl attaches an allocated library context to the easy\nhandle's state and passes it to OpenSSL without acquiring an ownership\nreference; destroying the easy handle prematurely frees this context while\nthe\nactive connection retains a dangling pointer, leading to a\nheap-use-after-free\nupon subsequent I/O or post-handshake operations.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-80229","https://curl.se/docs/CVE-2026-80229.html","https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d9"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d9"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"upstream","status":"released","description":"8.22.0~rc3-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-19931","published":"2026-09-06T18:17:00","updated_at":"2026-09-16T10:38:42.747675+00:00","description":"\nA flaw in libcurl makes it wrongly reuse an HTTP connection setup for a\ngiven\nhostname using Negotiate authentication, when the initial request is done\nusing empty credentials. This can make user B's request get sent over user\nA's\npreviously authenticated connection.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-19931","https://curl.se/docs/CVE-2026-19931.html","https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"upstream","status":"released","description":"8.22.0~rc2-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-18924","published":"2026-09-06T18:17:00","updated_at":"2026-09-16T10:36:12.026444+00:00","description":"\nA flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent\nhandle is set to share connections with other handles, can lead to\nuse-after-free in the cleanup process.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-18924","https://curl.se/docs/CVE-2026-18924.html","https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"upstream","status":"released","description":"8.22.0~rc2-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-13608","published":"2026-09-06T18:17:00","updated_at":"2026-09-16T10:42:08.033800+00:00","description":"\nA flaw in the libcurl SASL negotiation for LDAP authentication allows an\nincomplete handshake sequence to be misinterpreted as a successful\ncryptographic verification. An attacker executing a Man-in-the-Middle\n(MITM)\nattack can inject a premature or shortcut response that bypasses complete\npeer\nvalidation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-13608","https://curl.se/docs/CVE-2026-13608.html","https://github.com/curl/curl/pull/22213/changes/1a00e2a73675c9521d214aafd6c02b553bfeb022"],"bugs":[""],"patches":{"curl":["upstream: https://github.com/curl/curl/pull/22213/changes/1a00e2a73675c9521d214aafd6c02b553bfeb022"]},"tags":{},"packages":[{"name":"curl","source":"https://ubuntu.com/security/cve?package=curl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=curl","debian":"https://tracker.debian.org/pkg/curl","statuses":[{"release_codename":"upstream","status":"released","description":"8.22.0~rc2-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6554","published":"2026-09-05T19:16:00","updated_at":"2026-09-16T10:44:53.450238+00:00","description":"\nlibpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as\na signed integer to implement looping via backward jumps, but it does not\nlimit the number of loop iterations. In particular uncommon use cases a\ncrafted filter program can cause the interpreter to loop infinitely.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6554"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146825"],"patches":{"libpcap":[]},"tags":{},"packages":[{"name":"libpcap","source":"https://ubuntu.com/security/cve?package=libpcap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpcap","debian":"https://tracker.debian.org/pkg/libpcap","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-6244","published":"2026-09-05T19:16:00","updated_at":"2026-09-16T10:43:42.720801+00:00","description":"\nlibpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does\nnot check whether the immediate value is zero. In particular uncommon use\ncases a crafted filter program can cause a division by zero.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-6244"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146825"],"patches":{"libpcap":[]},"tags":{},"packages":[{"name":"libpcap","source":"https://ubuntu.com/security/cve?package=libpcap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpcap","debian":"https://tracker.debian.org/pkg/libpcap","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-31912","published":"2026-09-05T19:16:00","updated_at":"2026-09-16T10:39:00.383057+00:00","description":"\nlibpcap BPF interpreter detects neither reaching the end of the filter\nprogram buffer due to lack of a return instruction nor executing a jump\ninstruction with an offset that translates to a pointer outside of the\nbuffer. In particular uncommon use cases a crafted filter program can\ncause the interpreter to try reading the OS process memory in the 32GiB\naround the buffer on 64-bit architectures and in the entire address space\non 32-bit architectures.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-31912"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146825"],"patches":{"libpcap":[]},"tags":{},"packages":[{"name":"libpcap","source":"https://ubuntu.com/security/cve?package=libpcap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpcap","debian":"https://tracker.debian.org/pkg/libpcap","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-31911","published":"2026-09-05T19:16:00","updated_at":"2026-09-16T10:38:03.973534+00:00","description":"\nlibpcap BPF interpreter calls abort() if it encounters a BPF instruction\nthat has an invalid opcode. In particular uncommon use cases a crafted\nfilter program can terminate the OS process.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-31911"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146825"],"patches":{"libpcap":[]},"tags":{},"packages":[{"name":"libpcap","source":"https://ubuntu.com/security/cve?package=libpcap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpcap","debian":"https://tracker.debian.org/pkg/libpcap","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-18313","published":"2026-09-05T19:16:00","updated_at":"2026-09-16T10:36:54.297021+00:00","description":"\nrpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ\nor RPCAP_MSG_STARTCAP_REQ message received from the client, but it never\nfrees the memory, so it leaks memory even under normal use. A malicious\nclient can cause the server to leak memory substantially faster.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-18313"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146825"],"patches":{"libpcap":[]},"tags":{},"packages":[{"name":"libpcap","source":"https://ubuntu.com/security/cve?package=libpcap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpcap","debian":"https://tracker.debian.org/pkg/libpcap","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-18238","published":"2026-09-05T19:16:00","updated_at":"2026-09-16T10:38:42.747675+00:00","description":"\nThe rpcap client code that processes a RPCAP_MSG_PACKET message received\nfrom the server incorrectly validates its headers. A malicious server can\nsend a crafted message and cause the client to treat up to 20 bytes of the\nclient process memory beyond the end of the buffer as if it was a part of\nthe captured packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-18238"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146825"],"patches":{"libpcap":[]},"tags":{},"packages":[{"name":"libpcap","source":"https://ubuntu.com/security/cve?package=libpcap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpcap","debian":"https://tracker.debian.org/pkg/libpcap","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-0799","published":"2026-09-05T19:16:00","updated_at":"2026-09-16T10:36:12.026444+00:00","description":"\nIn BPF instructions that load/store a value from/to a scratch memory\nregister the register index is an unsigned 32-bit integer and must not\nexceed 15, but libpcap BPF interpreter does not validate the value. In\nparticular uncommon use cases a crafted filter program can cause the\ninterpreter to try reading and writing the OS process memory in the 16GiB\nstarting at the current stack frame on 64-bit architectures and in the\nentire address space on 32-bit architectures.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-0799"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146825"],"patches":{"libpcap":[]},"tags":{},"packages":[{"name":"libpcap","source":"https://ubuntu.com/security/cve?package=libpcap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libpcap","debian":"https://tracker.debian.org/pkg/libpcap","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-15614","published":"2026-09-05T12:16:00","updated_at":"2026-09-16T10:29:52.622130+00:00","description":"\nugrep before 7.6.0 contains a heap buffer over-read vulnerability in the\nLZW decompressor when processing crafted .Z archive files. Attackers can\nsupply malformed .Z files that cause the decompressor to read one byte past\nthe allocated heap buffer, potentially crashing the process.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-15614","https://github.com/Genivia/ugrep/issues/511"],"bugs":[""],"patches":{"ugrep":[]},"tags":{},"packages":[{"name":"ugrep","source":"https://ubuntu.com/security/cve?package=ugrep","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ugrep","debian":"https://tracker.debian.org/pkg/ugrep","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.6.0+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-86145","published":"2026-09-05T06:17:00","updated_at":"2026-09-16T16:47:52.359380+00:00","description":"\nPCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because\nreuse of a cached workspace block, in a recursive DFA matching workspace,\nlacks a size check (even though a newly allocated block, for the same\npurpose, does have a size check). This outcome requires an\nattacker-controlled regular expression, or a recursive pattern in\nconjunction with a small heap limit (this can be set through the API).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":8.2,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-86145","https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf"],"bugs":[""],"patches":{"pcre2":[]},"tags":{},"packages":[{"name":"pcre2","source":"https://ubuntu.com/security/cve?package=pcre2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcre2","debian":"https://tracker.debian.org/pkg/pcre2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.48-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-86144","published":"2026-09-05T05:17:00","updated_at":"2026-09-16T16:42:44.421363+00:00","description":"\nIn xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and\nxmlXIncludeProcessTree do not propagate parseFlags. This has security\nrelevance for, for example, the XML_PARSE_NONET flag, if (without it) a\ncustom resource loader accesses the internet and triggers XML external\nentity injection, SSRF, or a denial of service (e.g., for an\nattacker-controlled internet resource that is intentionally slow).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-86144"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146744"],"patches":{"libxml2":[]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.15.4+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-86143","published":"2026-09-05T05:17:00","updated_at":"2026-09-16T16:41:38.995980+00:00","description":"\nIn xmlIO in libxml2 before 2.15.4, an inconsistency in\nxmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write\ncallbacks, aka a lack of a check for integer overflow before calling\nwritecallback. This has security relevance for many types of uses of that\nlength value within a callback.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-86143","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1111"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146744"],"patches":{"libxml2":[]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.15.4+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-86142","published":"2026-09-05T05:17:00","updated_at":"2026-09-16T16:45:29.233831+00:00","description":"\nIn libxml2 before 2.15.4, there is a heap-based buffer overflow in\nxmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-86142","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1113"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146744"],"patches":{"libxml2":[]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.15.4+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-86141","published":"2026-09-05T05:17:00","updated_at":"2026-09-16T16:49:12.235108+00:00","description":"\nxmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in\nxmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a\nstring length after NULL checking.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":2.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-86141","https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1107"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146744"],"patches":{"libxml2":[]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.15.4+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-86140","published":"2026-09-05T05:17:00","updated_at":"2026-09-16T16:42:44.421363+00:00","description":"\nIn libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat\nstack-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":8.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-86140"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146744"],"patches":{"libxml2":[]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"upstream","status":"released","description":"2.15.4+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-86139","published":"2026-09-05T05:17:00","updated_at":"2026-09-16T16:44:01.665683+00:00","description":"\nIn libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-86139"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146744"],"patches":{"libxml2":[]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.15.4+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-86138","published":"2026-09-05T05:17:00","updated_at":"2026-09-16T16:50:21.639762+00:00","description":"\nIn libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer\noverflow and resultant heap-based buffer overflow.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-86138"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1146744"],"patches":{"libxml2":[]},"tags":{},"packages":[{"name":"libxml2","source":"https://ubuntu.com/security/cve?package=libxml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libxml2","debian":"https://tracker.debian.org/pkg/libxml2","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.15.4+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":1800,"limit":20,"total_results":79316}