{"cves":[{"id":"CVE-2025-1754","published":"2025-06-26T06:15:00","updated_at":"2025-07-02T17:22:54.061249+00:00","description":"\nAn issue has been discovered in GitLab CE/EE affecting all versions from\n17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could\nhave allowed unauthenticated attackers to upload arbitrary files to public\nprojects by sending crafted API requests, potentially leading to resource\nabuse and unauthorized content storage.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"GitLab isn't maintainable as a distro package, and was removed\nfrom Ubuntu because of this. We will not be fixing security\nissues in the gitlab package in Xenial."}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-1754"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-6174","published":"2025-06-26T00:00:00","updated_at":"2025-08-01T19:45:38.261961+00:00","description":"\nWhen a non-x86 platform is detected, cloud-init grants root access to a\nhardcoded url with a local IP address. To prevent this, cloud-init default\nconfigurations disable platform enumeration.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-6174","https://github.com/canonical/cloud-init/releases/tag/25.1.3","https://ubuntu.com/security/notices/USN-7677-1"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/cloud-init/+bug/2069607"],"patches":{"cloud-init":[]},"tags":{},"packages":[{"name":"cloud-init","source":"https://ubuntu.com/security/cve?package=cloud-init","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cloud-init","debian":"https://tracker.debian.org/pkg/cloud-init","statuses":[{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.1.3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"23.1.2-0ubuntu0~18.04.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"24.4.1-0ubuntu0~20.04.3+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"25.1.4-0ubuntu0~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"25.1.4-0ubuntu0~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"25.1.4-0ubuntu0~25.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-7677-1"],"notices":[{"id":"USN-7677-1","title":"cloud-init vulnerabilities","summary":"Several security issues were fixed in cloud-init.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-07-28T22:20:39.828672","description":"Harry Sintonen discovered that the hotplugd socket in cloud-init was world\nwritable. An attacker could possibly use this issue to send hotplug-hook\ncommands. (CVE-2024-11584)\n\nIt was discovered that cloud-init granted root access to a hardcoded URL\nwith a local IP address when a non-x86 platform is detected. An attacker\ncould possibly impersonate an OpenStack endpoint and provide root\nconfiguration data. (CVE-2024-6174)","is_hidden":false,"release_packages":{"bionic":[{"name":"cloud-init","version":"23.1.2-0ubuntu0~18.04.1+esm1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"23.1.2-0ubuntu0~18.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"cloud-init","version":"24.4.1-0ubuntu0~20.04.3+esm1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"24.4.1-0ubuntu0~20.04.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"cloud-init","version":"25.1.4-0ubuntu0~22.04.1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"25.1.4-0ubuntu0~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~22.04.1","pocket":"security"}],"noble":[{"name":"cloud-init","version":"25.1.4-0ubuntu0~24.04.1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"25.1.4-0ubuntu0~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~24.04.1","pocket":"security"}],"plucky":[{"name":"cloud-init","version":"25.1.4-0ubuntu0~25.04.1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"25.1.4-0ubuntu0~25.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~25.04.1","pocket":"security"},{"name":"cloud-init-base","version":"25.1.4-0ubuntu0~25.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~25.04.1","pocket":"security"},{"name":"cloud-init-cloud-sigma","version":"25.1.4-0ubuntu0~25.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~25.04.1","pocket":"security"},{"name":"cloud-init-smart-os","version":"25.1.4-0ubuntu0~25.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~25.04.1","pocket":"security"}],"xenial":[{"name":"cloud-init","version":"21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"},{"name":"ec2-init","version":"21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"},{"name":"grub-legacy-ec2","version":"21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2024-6174","CVE-2024-11584"]}]},{"id":"CVE-2024-11584","published":"2025-06-26T00:00:00","updated_at":"2025-08-01T19:44:21.642435+00:00","description":"\ncloud-init through 25.1.2 includes the systemd socket\nunit cloud-init-hotplugd.socket with default SocketMode that grants 0666\npermissions, making it world-writable. This is used for the\n\"/run/cloud-init/hook-hotplug-cmd\" FIFO. An unprivileged user could\ntrigger hotplug-hook commands.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-11584","https://github.com/canonical/cloud-init/pull/6265/commits/6e10240a7f0a2d6110b398640b3fd46cfa9a7cf3","https://github.com/canonical/cloud-init/releases/tag/25.1.3","https://ubuntu.com/security/notices/USN-7677-1"],"bugs":[""],"patches":{"cloud-init":[]},"tags":{},"packages":[{"name":"cloud-init","source":"https://ubuntu.com/security/cve?package=cloud-init","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=cloud-init","debian":"https://tracker.debian.org/pkg/cloud-init","statuses":[{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"25.1.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"23.1.2-0ubuntu0~18.04.1+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"24.4.1-0ubuntu0~20.04.3+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"jammy","status":"released","description":"25.1.4-0ubuntu0~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"25.1.4-0ubuntu0~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"25.1.4-0ubuntu0~25.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-7677-1"],"notices":[{"id":"USN-7677-1","title":"cloud-init vulnerabilities","summary":"Several security issues were fixed in cloud-init.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-07-28T22:20:39.828672","description":"Harry Sintonen discovered that the hotplugd socket in cloud-init was world\nwritable. An attacker could possibly use this issue to send hotplug-hook\ncommands. (CVE-2024-11584)\n\nIt was discovered that cloud-init granted root access to a hardcoded URL\nwith a local IP address when a non-x86 platform is detected. An attacker\ncould possibly impersonate an OpenStack endpoint and provide root\nconfiguration data. (CVE-2024-6174)","is_hidden":false,"release_packages":{"bionic":[{"name":"cloud-init","version":"23.1.2-0ubuntu0~18.04.1+esm1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"23.1.2-0ubuntu0~18.04.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"cloud-init","version":"24.4.1-0ubuntu0~20.04.3+esm1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"24.4.1-0ubuntu0~20.04.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"}],"jammy":[{"name":"cloud-init","version":"25.1.4-0ubuntu0~22.04.1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"25.1.4-0ubuntu0~22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~22.04.1","pocket":"security"}],"noble":[{"name":"cloud-init","version":"25.1.4-0ubuntu0~24.04.1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"25.1.4-0ubuntu0~24.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~24.04.1","pocket":"security"}],"plucky":[{"name":"cloud-init","version":"25.1.4-0ubuntu0~25.04.1","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"25.1.4-0ubuntu0~25.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~25.04.1","pocket":"security"},{"name":"cloud-init-base","version":"25.1.4-0ubuntu0~25.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~25.04.1","pocket":"security"},{"name":"cloud-init-cloud-sigma","version":"25.1.4-0ubuntu0~25.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~25.04.1","pocket":"security"},{"name":"cloud-init-smart-os","version":"25.1.4-0ubuntu0~25.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":"https://launchpad.net/ubuntu/+source/cloud-init/25.1.4-0ubuntu0~25.04.1","pocket":"security"}],"xenial":[{"name":"cloud-init","version":"21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2","description":"initialization and customization tool for cloud instances","is_source":true},{"name":"cloud-init","version":"21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"},{"name":"ec2-init","version":"21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"},{"name":"grub-legacy-ec2","version":"21.1-19-gbad84ad4-0ubuntu1~16.04.4+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/cloud-init","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2024-6174","CVE-2024-11584"]}]},{"id":"CVE-2025-45333","published":"2025-06-25T20:15:00","updated_at":"2025-07-02T17:22:14.983338+00:00","description":"\nberkeley-abc abc 1.1 contains a Null Pointer Dereference (NPD)\nvulnerability in the Abc_NtkCecFraigPart function of its data processing\nmodule, leading to unpredictable program behavior, causing segmentation\nfaults, and program crashes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-45333","https://gist.github.com/QiuYitai/eb49750fe58e39ce685cfd87a41eacb9","https://github.com/berkeley-abc/abc/pull/383"],"bugs":[""],"patches":{"berkeley-abc":[]},"tags":{},"packages":[{"name":"berkeley-abc","source":"https://ubuntu.com/security/cve?package=berkeley-abc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=berkeley-abc","debian":"https://tracker.debian.org/pkg/berkeley-abc","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-6442","published":"2025-06-25T17:15:00","updated_at":"2025-10-27T16:51:02.870665+00:00","description":"\nRuby WEBrick read_header HTTP Request Smuggling Vulnerability. This\nvulnerability allows remote attackers to smuggle arbitrary HTTP requests on\naffected installations of Ruby WEBrick. This issue is exploitable when the\nproduct is deployed behind an HTTP proxy that fulfills specific conditions.\nThe specific flaw exists within the read_headers method. The issue results\nfrom the inconsistent parsing of terminators of HTTP headers. An attacker\ncan leverage this vulnerability to smuggle arbitrary HTTP requests. Was\nZDI-CAN-21876.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-6442","https://www.zerodayinitiative.com/advisories/ZDI-25-414/","https://ubuntu.com/security/notices/USN-7709-1","https://ubuntu.com/security/notices/USN-7840-1"],"bugs":[""],"patches":{"ruby-webrick":["upstream: https://github.com/ruby/webrick/commit/ee60354bcb84ec33b9245e1d1aa6e1f7e8132101"],"jruby":[],"ruby2.3":[],"ruby2.5":[],"ruby2.7":[]},"tags":{},"packages":[{"name":"jruby","source":"https://ubuntu.com/security/cve?package=jruby","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jruby","debian":"https://tracker.debian.org/pkg/jruby","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"vulnerable code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"vulnerable code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"vulnerable code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"vulnerable code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"ruby-webrick","source":"https://ubuntu.com/security/cve?package=ruby-webrick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby-webrick","debian":"https://tracker.debian.org/pkg/ruby-webrick","statuses":[{"release_codename":"resolute","status":"released","description":"1.9.1-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.7.0-3ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.8.1-1ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1.8.1-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.9.1-1","component":null,"pocket":"security"}]},{"name":"ruby2.3","source":"https://ubuntu.com/security/cve?package=ruby2.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.3","debian":"https://tracker.debian.org/pkg/ruby2.3","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.3.1-2~ubuntu16.04.16+esm11","component":null,"pocket":"esm-infra"}]},{"name":"ruby2.5","source":"https://ubuntu.com/security/cve?package=ruby2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.5","debian":"https://tracker.debian.org/pkg/ruby2.5","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2.5.1-1ubuntu1.16+esm6","component":null,"pocket":"esm-infra"}]},{"name":"ruby2.7","source":"https://ubuntu.com/security/cve?package=ruby2.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ruby2.7","debian":"https://tracker.debian.org/pkg/ruby2.7","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.7.0-5ubuntu1.18+esm3","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-7709-1","USN-7840-1"],"notices":[{"id":"USN-7709-1","title":"WEBrick vulnerability","summary":"WEBrick could allow an HTTP request smuggling attack.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-08-21T13:53:54.347133","description":"It was discovered that WEBrick incorrectly parsed HTTP headers. In\nconfigurations where WEBrick is placed behind an HTTP proxy, a remote\nattacker could possibly use this issue to perform an HTTP Request Smuggling\nattack.","is_hidden":false,"release_packages":{"jammy":[{"name":"ruby-webrick","version":"1.7.0-3ubuntu0.2","description":"HTTP server toolkit in Ruby","is_source":true},{"name":"ruby-webrick","version":"1.7.0-3ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-webrick","version_link":"https://launchpad.net/ubuntu/+source/ruby-webrick/1.7.0-3ubuntu0.2","pocket":"security"}],"noble":[{"name":"ruby-webrick","version":"1.8.1-1ubuntu0.2","description":"HTTP server toolkit in Ruby","is_source":true},{"name":"ruby-webrick","version":"1.8.1-1ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-webrick","version_link":"https://launchpad.net/ubuntu/+source/ruby-webrick/1.8.1-1ubuntu0.2","pocket":"security"}],"plucky":[{"name":"ruby-webrick","version":"1.8.1-1ubuntu1.1","description":"HTTP server toolkit in Ruby","is_source":true},{"name":"ruby-webrick","version":"1.8.1-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-webrick","version_link":"https://launchpad.net/ubuntu/+source/ruby-webrick/1.8.1-1ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-6442"]},{"id":"USN-7840-1","title":"Ruby vulnerabilities","summary":"Several security issues were fixed in Ruby.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-10-27T14:39:58.774922","description":"It was discovered that the REXML module bunded into Ruby incorrectly\nhandled parsing XML documents with repeated instances of certain\ncharacters. An attacker could possibly use this issue to cause REXML to\nconsume excessive resources, leading to a denial of service. Ubuntu 18.04\nLTS and Ubuntu 20.04 LTS were previously addressed in USN-7256-1 and\nUSN-7734-1. This update addresses the issue in Ubuntu 16.04 LTS.\n(CVE-2024-35176)\n\nIt was discovered that the REXML module bunded into Ruby incorrectly\nhandled parsing XML documents with repeated instances of certain\ncharacters. An attacker could possibly use this issue to cause REXML to\nconsume excessive resources, leading to a denial of service. Ubuntu 20.04\nLTS was previously addressed in USN-7256-1. This update addresses the issue\nin Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-39908, CVE-2024-41123)\n\nIt was discovered that the REXML module bunded into Ruby incorrectly\nhandled parsing XML documents with many entity expansions. An attacker\ncould possibly use this issue to cause REXML to consume excessive\nresources, leading to a denial of service. Ubuntu 20.04 LTS was previously\naddressed in USN-7091-2. This update addresses the issue in Ubuntu 16.04\nLTS and Ubuntu 18.04 LTS. (CVE-2024-41946)\n\nIt was discovered that the WEBrick module bundled into Ruby incorrectly\nhandled having both a Content-Length header and a Transfer-Encoding header.\nA remote attacker could possibly use this issue to perform a HTTP request\nsmuggling attack. (CVE-2024-47220)\n\nIt was discovered that the WEBrick module bundled into Ruby incorrectly\nparsed HTTP headers. In configurations where the WEBrick module is placed\nbehind an HTTP proxy, a remote attacker could possibly use this issue to\nperform an HTTP Request Smuggling attack. (CVE-2025-6442)","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby2.5","version":"2.5.1-1ubuntu1.16+esm6","description":"Object-oriented scripting language","is_source":true},{"name":"libruby2.5","version":"2.5.1-1ubuntu1.16+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.5","version":"2.5.1-1ubuntu1.16+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.5-dev","version":"2.5.1-1ubuntu1.16+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.5-doc","version":"2.5.1-1ubuntu1.16+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.5","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"ruby2.7","version":"2.7.0-5ubuntu1.18+esm3","description":"Object-oriented scripting language","is_source":true},{"name":"libruby2.7","version":"2.7.0-5ubuntu1.18+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.7","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.7","version":"2.7.0-5ubuntu1.18+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.7","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.7-dev","version":"2.7.0-5ubuntu1.18+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.7","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.7-doc","version":"2.7.0-5ubuntu1.18+esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.7","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.16+esm11","description":"Object-oriented scripting language","is_source":true},{"name":"libruby2.3","version":"2.3.1-2~ubuntu16.04.16+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.3","version":"2.3.1-2~ubuntu16.04.16+esm11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.3-dev","version":"2.3.1-2~ubuntu16.04.16+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.3-doc","version":"2.3.1-2~ubuntu16.04.16+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":null,"pocket":"esm-infra"},{"name":"ruby2.3-tcltk","version":"2.3.1-2~ubuntu16.04.16+esm11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ruby2.3","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2024-47220","CVE-2024-41946","CVE-2024-41123","CVE-2025-6442","CVE-2024-35176","CVE-2024-39908"]}]},{"id":"CVE-2025-52999","published":"2025-06-25T17:15:00","updated_at":"2026-07-10T19:11:54.960325+00:00","description":"\njackson-core contains core low-level incremental (\"streaming\") parser and\ngenerator abstractions used by Jackson Data Processor. In versions prior to\n2.15.0, if a user parses an input file and it has deeply nested data,\nJackson could end up throwing a StackoverflowError if the depth is\nparticularly large. jackson-core 2.15.0 contains a configurable limit for\nhow deep Jackson will traverse in an input document, defaulting to an\nallowable depth of 1000. jackson-core will throw a\nStreamConstraintsException if the limit is reached. jackson-databind also\nbenefits from this change because it uses jackson-core to parse JSON\ninputs. As a workaround, users should avoid parsing input files from\nuntrusted sources.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-52999","https://github.com/FasterXML/jackson-core/pull/943","https://github.com/FasterXML/jackson-core/security/advisories/GHSA-h46c-h94j-95f3"],"bugs":[""],"patches":{"jackson-core":[]},"tags":{},"packages":[{"name":"jackson-core","source":"https://ubuntu.com/security/cve?package=jackson-core","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=jackson-core","debian":"https://tracker.debian.org/pkg/jackson-core","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-52893","published":"2025-06-25T17:15:00","updated_at":"2025-06-25T19:33:16.553164+00:00","description":"\nOpenBao exists to provide a software solution to manage, store, and\ndistribute sensitive data including secrets, certificates, and keys.\nOpenBao before v2.3.0 may leak sensitive information in logs when\nprocessing malformed data. This is separate from the earlier HCSEC-2025-09\n/ CVE-2025-4166. This issue has been fixed in OpenBao v2.3.0 and later.\nLike with HCSEC-2025-09, there is no known workaround except to ensure\nproperly formatted requests from all clients.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-52893","https://discuss.hashicorp.com/t/hcsec-2025-09-vault-may-expose-sensitive-information-in-error-logs-when-processing-malformed-data-with-the-kv-v2-plugin/74717","https://github.com/go-viper/mapstructure/commit/ed3f92181528ff776a0324107b8b55026e93766a","https://github.com/go-viper/mapstructure/pull/105","https://github.com/go-viper/mapstructure/releases/tag/v2.3.0","https://github.com/openbao/openbao/commit/cf5e920badbf96b41253534a3fd5ff5063bf4b30","https://github.com/openbao/openbao/security/advisories/GHSA-8f5r-8cmq-7fmq"],"bugs":[""],"patches":{"golang-github-go-viper-mapstructure":[]},"tags":{},"packages":[{"name":"golang-github-go-viper-mapstructure","source":"https://ubuntu.com/security/cve?package=golang-github-go-viper-mapstructure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-go-viper-mapstructure","debian":"https://tracker.debian.org/pkg/golang-github-go-viper-mapstructure","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-52890","published":"2025-06-25T17:15:00","updated_at":"2025-06-25T19:33:16.553164+00:00","description":"\nIncus is a system container and virtual machine manager. When using an ACL\non a device connected to a bridge, Incus versions 6.12 and 6.13generates\nnftables rules that partially bypass security options\n`security.mac_filtering`, `security.ipv4_filtering` and\n`security.ipv6_filtering`. This can lead to ARP spoofing on the bridge and\nto fully spoof another VM/container on the same bridge. Commit\n254dfd2483ab8de39b47c2258b7f1cf0759231c8 contains a patch for the issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-52890","https://github.com/lxc/incus/commit/254dfd2483ab8de39b47c2258b7f1cf0759231c8","https://github.com/lxc/incus/security/advisories/GHSA-p7fw-vjjm-2rwp"],"bugs":[""],"patches":{"incus":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-52889","published":"2025-06-25T17:15:00","updated_at":"2025-06-25T19:33:16.553164+00:00","description":"\nIncus is a system container and virtual machine manager. When using an ACL\non a device connected to a bridge, Incus version 6.12 and 6.13 generates\nnftables rules for local services (DHCP, DNS...) that partially bypass\nsecurity options `security.mac_filtering`, `security.ipv4_filtering` and\n`security.ipv6_filtering`. This can lead to DHCP pool exhaustion and opens\nthe door for other attacks. A patch is available at commit\n2516fb19ad8428454cb4edfe70c0a5f0dc1da214.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.4,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-52889","https://github.com/lxc/incus/commit/2516fb19ad8428454cb4edfe70c0a5f0dc1da214","https://github.com/lxc/incus/commit/a7c33301738aede3c035063e973b1d885d9bac7c","https://github.com/lxc/incus/security/advisories/GHSA-9q7c-qmhm-jv86"],"bugs":[""],"patches":{"incus":[]},"tags":{},"packages":[{"name":"incus","source":"https://ubuntu.com/security/cve?package=incus","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=incus","debian":"https://tracker.debian.org/pkg/incus","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-5987","published":"2025-06-25T00:00:00","updated_at":"2026-01-09T07:52:30.500292+00:00","description":"\nA flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL\nlibrary. If an attacker manages to exhaust the heap space, this error is\nnot detected and may lead to libssh using a partially initialized cipher\ncontext. This occurs because the OpenSSL error code returned aliases with\nthe SSH_OK code, resulting in libssh not properly detecting the error\nreturned by the OpenSSL library. This issue can lead to undefined behavior,\nincluding compromised data confidentiality and integrity or crashes.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-5987","https://www.libssh.org/security/advisories/CVE-2025-5987.txt","https://ubuntu.com/security/notices/USN-7619-1"],"bugs":[""],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=90b4845e0c98574bbf7bea9e97796695f064bf57"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"noble","status":"released","description":"0.10.6-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"0.10.6-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"0.11.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.11.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-7619-1"],"notices":[{"id":"USN-7619-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-07-07T12:29:26.323110","description":"Ronald Crane discovered that libssh incorrectly handled certain base64\nconversions. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-4877)\n\nRonald Crane discovered that libssh incorrectly handled the\nprivatekey_from_file() function. An attacker could use this issue to cause\nlibssh to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2025-4878)\n\nRonald Crane discovered that libssh incorrectly handled certain memory\noperations in the sftp server. An attacker could possibly use this issue\nto cause libssh to crash, resulting in a denial of service.\n(CVE-2025-5318, CVE-2025-5449)\n\nRonald Crane discovered that libssh incorrectly handled exporting keys. An\nattacker could possibly use this issue to cause libssh to crash, resulting\nin a denial of service. This issue only affected Ubuntu 24.04 LTS, Ubuntu\n24.10, and Ubuntu 25.04. (CVE-2025-5351)\n\nRonald Crane discovered that libssh incorrectly handled the ssh_kdf()\nfunction. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-5372)\n\nRonald Crane discovered that libssh incorrectly handled the ChaCha20\ncipher. An attacker could possibly use this issue to cause libssh to\nuse partially initialized cypher content. This issue only affected Ubuntu\n24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-5987)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.4","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"}],"oracular":[{"name":"libssh","version":"0.10.6-3ubuntu1.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"}],"plucky":[{"name":"libssh","version":"0.11.1-1ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-5351","CVE-2025-5372","CVE-2025-4877","CVE-2025-5318","CVE-2025-5987","CVE-2025-4878","CVE-2025-5449"]}]},{"id":"CVE-2025-5449","published":"2025-06-25T00:00:00","updated_at":"2026-01-09T06:01:55.406952+00:00","description":"\nA flaw was found in the SFTP server message decoding logic of libssh. The\nissue occurs due to an incorrect packet length check that allows an integer\noverflow when handling large payload sizes on 32-bit systems. This issue\nleads to failed memory allocation and causes the server process to crash,\nresulting in a denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-5449","https://www.libssh.org/security/advisories/CVE-2025-5449.txt","https://ubuntu.com/security/notices/USN-7619-1"],"bugs":[""],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=261612179f740bc62ba363d98b3bd5e5573a811f","upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=3443aec90188d6aab9282afc80a81df5ab72c4da","upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=78485f446af9b30e37eb8f177b81940710d54496","upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=f79ec51b7fd519dbc5737a7ba826e3ed093f6ceb","upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=5504ff40515439a5fecbb17da7483000c4d12eb7"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"upstream","status":"released","description":"0.11.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"0.11.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-7619-1"],"notices":[{"id":"USN-7619-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-07-07T12:29:26.323110","description":"Ronald Crane discovered that libssh incorrectly handled certain base64\nconversions. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-4877)\n\nRonald Crane discovered that libssh incorrectly handled the\nprivatekey_from_file() function. An attacker could use this issue to cause\nlibssh to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2025-4878)\n\nRonald Crane discovered that libssh incorrectly handled certain memory\noperations in the sftp server. An attacker could possibly use this issue\nto cause libssh to crash, resulting in a denial of service.\n(CVE-2025-5318, CVE-2025-5449)\n\nRonald Crane discovered that libssh incorrectly handled exporting keys. An\nattacker could possibly use this issue to cause libssh to crash, resulting\nin a denial of service. This issue only affected Ubuntu 24.04 LTS, Ubuntu\n24.10, and Ubuntu 25.04. (CVE-2025-5351)\n\nRonald Crane discovered that libssh incorrectly handled the ssh_kdf()\nfunction. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-5372)\n\nRonald Crane discovered that libssh incorrectly handled the ChaCha20\ncipher. An attacker could possibly use this issue to cause libssh to\nuse partially initialized cypher content. This issue only affected Ubuntu\n24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-5987)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.4","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"}],"oracular":[{"name":"libssh","version":"0.10.6-3ubuntu1.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"}],"plucky":[{"name":"libssh","version":"0.11.1-1ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-5351","CVE-2025-5372","CVE-2025-4877","CVE-2025-5318","CVE-2025-5987","CVE-2025-4878","CVE-2025-5449"]}]},{"id":"CVE-2025-5372","published":"2025-06-25T00:00:00","updated_at":"2025-07-10T19:14:19.166514+00:00","description":"\nA flaw was found in libssh versions built with OpenSSL versions older than\n3.0, specifically in the ssh_kdf() function responsible for key derivation.\nDue to inconsistent interpretation of return values where OpenSSL uses 0 to\nindicate failure and libssh uses 0 for success—the function may mistakenly\nreturn a success status even when key derivation fails. This results in\nuninitialized cryptographic key buffers being used in subsequent\ncommunication, potentially compromising SSH sessions' confidentiality,\nintegrity, and availability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-5372","https://www.libssh.org/security/advisories/CVE-2025-5372.txt","https://ubuntu.com/security/notices/USN-7619-1"],"bugs":[""],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=f13b91c2d87f2b75540ebdc93b8958594976e985","upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=a9d8a3d44829cf9182b252bc951f35fb0d573972"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"jammy","status":"released","description":"0.9.6-2ubuntu0.22.04.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.10.6-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"0.10.6-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"0.11.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.11.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [changes too intrusive]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"changes too intrusive","component":null,"pocket":"security"}]}],"notices_ids":["USN-7619-1"],"notices":[{"id":"USN-7619-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-07-07T12:29:26.323110","description":"Ronald Crane discovered that libssh incorrectly handled certain base64\nconversions. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-4877)\n\nRonald Crane discovered that libssh incorrectly handled the\nprivatekey_from_file() function. An attacker could use this issue to cause\nlibssh to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2025-4878)\n\nRonald Crane discovered that libssh incorrectly handled certain memory\noperations in the sftp server. An attacker could possibly use this issue\nto cause libssh to crash, resulting in a denial of service.\n(CVE-2025-5318, CVE-2025-5449)\n\nRonald Crane discovered that libssh incorrectly handled exporting keys. An\nattacker could possibly use this issue to cause libssh to crash, resulting\nin a denial of service. This issue only affected Ubuntu 24.04 LTS, Ubuntu\n24.10, and Ubuntu 25.04. (CVE-2025-5351)\n\nRonald Crane discovered that libssh incorrectly handled the ssh_kdf()\nfunction. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-5372)\n\nRonald Crane discovered that libssh incorrectly handled the ChaCha20\ncipher. An attacker could possibly use this issue to cause libssh to\nuse partially initialized cypher content. This issue only affected Ubuntu\n24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-5987)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.4","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"}],"oracular":[{"name":"libssh","version":"0.10.6-3ubuntu1.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"}],"plucky":[{"name":"libssh","version":"0.11.1-1ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-5351","CVE-2025-5372","CVE-2025-4877","CVE-2025-5318","CVE-2025-5987","CVE-2025-4878","CVE-2025-5449"]}]},{"id":"CVE-2025-5351","published":"2025-06-25T00:00:00","updated_at":"2026-01-09T05:58:20.342294+00:00","description":"\nA flaw was found in the key export functionality of libssh. The issue\noccurs in the internal function responsible for converting cryptographic\nkeys into serialized formats. During error handling, a memory structure is\nfreed but not cleared, leading to a potential double free issue if an\nadditional failure occurs later in the function. This condition may result\nin heap corruption or application instability in low-memory scenarios,\nposing a risk to system reliability where key export operations are\nperformed.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-5351","https://www.libssh.org/security/advisories/CVE-2025-5351.txt","https://ubuntu.com/security/notices/USN-7619-1"],"bugs":[""],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=6ddb730a27338983851248af59b128b995aad256"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.10.6-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"0.10.6-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"0.11.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.11.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-7619-1"],"notices":[{"id":"USN-7619-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-07-07T12:29:26.323110","description":"Ronald Crane discovered that libssh incorrectly handled certain base64\nconversions. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-4877)\n\nRonald Crane discovered that libssh incorrectly handled the\nprivatekey_from_file() function. An attacker could use this issue to cause\nlibssh to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2025-4878)\n\nRonald Crane discovered that libssh incorrectly handled certain memory\noperations in the sftp server. An attacker could possibly use this issue\nto cause libssh to crash, resulting in a denial of service.\n(CVE-2025-5318, CVE-2025-5449)\n\nRonald Crane discovered that libssh incorrectly handled exporting keys. An\nattacker could possibly use this issue to cause libssh to crash, resulting\nin a denial of service. This issue only affected Ubuntu 24.04 LTS, Ubuntu\n24.10, and Ubuntu 25.04. (CVE-2025-5351)\n\nRonald Crane discovered that libssh incorrectly handled the ssh_kdf()\nfunction. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-5372)\n\nRonald Crane discovered that libssh incorrectly handled the ChaCha20\ncipher. An attacker could possibly use this issue to cause libssh to\nuse partially initialized cypher content. This issue only affected Ubuntu\n24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-5987)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.4","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"}],"oracular":[{"name":"libssh","version":"0.10.6-3ubuntu1.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"}],"plucky":[{"name":"libssh","version":"0.11.1-1ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-5351","CVE-2025-5372","CVE-2025-4877","CVE-2025-5318","CVE-2025-5987","CVE-2025-4878","CVE-2025-5449"]}]},{"id":"CVE-2025-4878","published":"2025-06-25T00:00:00","updated_at":"2025-08-26T10:58:38.950691+00:00","description":"\nA vulnerability was found in libssh, where an uninitialized variable exists\nunder certain conditions in the privatekey_from_file() function. This flaw\ncan be triggered if the file specified by the filename doesn't exist and\nmay lead to possible signing failures or heap corruption.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.6,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-4878","https://www.libssh.org/security/advisories/CVE-2025-4878.txt","https://ubuntu.com/security/notices/USN-7619-1","https://ubuntu.com/security/notices/USN-7696-1"],"bugs":[""],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=697650caa97eaf7623924c75f9fcfec6dd423cd1","upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=b35ee876adc92a208d47194772e99f9c71e0bedb"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"upstream","status":"released","description":"0.11.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.9.6-2ubuntu0.22.04.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.10.6-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"0.10.6-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"0.11.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"0.9.3-2ubuntu2.5+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.6.3-4.3ubuntu0.6+esm2","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-7619-1","USN-7696-1"],"notices":[{"id":"USN-7619-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-07-07T12:29:26.323110","description":"Ronald Crane discovered that libssh incorrectly handled certain base64\nconversions. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-4877)\n\nRonald Crane discovered that libssh incorrectly handled the\nprivatekey_from_file() function. An attacker could use this issue to cause\nlibssh to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2025-4878)\n\nRonald Crane discovered that libssh incorrectly handled certain memory\noperations in the sftp server. An attacker could possibly use this issue\nto cause libssh to crash, resulting in a denial of service.\n(CVE-2025-5318, CVE-2025-5449)\n\nRonald Crane discovered that libssh incorrectly handled exporting keys. An\nattacker could possibly use this issue to cause libssh to crash, resulting\nin a denial of service. This issue only affected Ubuntu 24.04 LTS, Ubuntu\n24.10, and Ubuntu 25.04. (CVE-2025-5351)\n\nRonald Crane discovered that libssh incorrectly handled the ssh_kdf()\nfunction. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-5372)\n\nRonald Crane discovered that libssh incorrectly handled the ChaCha20\ncipher. An attacker could possibly use this issue to cause libssh to\nuse partially initialized cypher content. This issue only affected Ubuntu\n24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-5987)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.4","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"}],"oracular":[{"name":"libssh","version":"0.10.6-3ubuntu1.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"}],"plucky":[{"name":"libssh","version":"0.11.1-1ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-5351","CVE-2025-5372","CVE-2025-4877","CVE-2025-5318","CVE-2025-5987","CVE-2025-4878","CVE-2025-5449"]},{"id":"USN-7696-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-08-14T06:35:13.360351","description":"Ronald Crane discovered that libssh incorrectly handled certain base64\nconversions. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-4877)\n\nRonald Crane discovered that libssh incorrectly handled the\nprivatekey_from_file() function. An attacker could use this issue to cause\nlibssh to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2025-4878)\n\nRonald Crane discovered that libssh incorrectly handled certain memory\noperations in the sftp server. An attacker could possibly use this issue\nto cause libssh to crash, resulting in a denial of service.\n(CVE-2025-5318)","is_hidden":false,"release_packages":{"bionic":[{"name":"libssh","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-dev","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-doc","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-4","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-dev","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"libssh","version":"0.9.3-2ubuntu2.5+esm1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-dev","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-doc","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-4","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-dev","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libssh","version":"0.6.3-4.3ubuntu0.6+esm2","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-dev","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-doc","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-4","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-dev","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2025-4877","CVE-2025-5318","CVE-2025-4878"]}]},{"id":"CVE-2025-4877","published":"2025-06-25T00:00:00","updated_at":"2025-08-29T11:37:28.973742+00:00","description":"\nThere's a vulnerability in the libssh package where when a libssh consumer\npasses in an unexpectedly large input buffer to ssh_get_fingerprint_hash()\nfunction. In such cases the bin_to_base64() function can experience an\ninteger overflow leading to a memory under allocation, when that happens\nit's possible that the program perform out of bounds write leading to a\nheap corruption.\nThis issue affects only 32-bits builds of libssh.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-4877","https://www.libssh.org/security/advisories/CVE-2025-4877.txt","https://ubuntu.com/security/notices/USN-7619-1","https://ubuntu.com/security/notices/USN-7696-1"],"bugs":[""],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.11&id=6fd9cc8ce3958092a1aae11f1f2e911b2747732d"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"jammy","status":"released","description":"0.9.6-2ubuntu0.22.04.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.11.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.10.6-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"0.10.6-3ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"0.11.1-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"0.9.3-2ubuntu2.5+esm1","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"0.6.3-4.3ubuntu0.6+esm2","component":null,"pocket":"esm-infra"}]}],"notices_ids":["USN-7619-1","USN-7696-1"],"notices":[{"id":"USN-7619-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-07-07T12:29:26.323110","description":"Ronald Crane discovered that libssh incorrectly handled certain base64\nconversions. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-4877)\n\nRonald Crane discovered that libssh incorrectly handled the\nprivatekey_from_file() function. An attacker could use this issue to cause\nlibssh to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2025-4878)\n\nRonald Crane discovered that libssh incorrectly handled certain memory\noperations in the sftp server. An attacker could possibly use this issue\nto cause libssh to crash, resulting in a denial of service.\n(CVE-2025-5318, CVE-2025-5449)\n\nRonald Crane discovered that libssh incorrectly handled exporting keys. An\nattacker could possibly use this issue to cause libssh to crash, resulting\nin a denial of service. This issue only affected Ubuntu 24.04 LTS, Ubuntu\n24.10, and Ubuntu 25.04. (CVE-2025-5351)\n\nRonald Crane discovered that libssh incorrectly handled the ssh_kdf()\nfunction. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-5372)\n\nRonald Crane discovered that libssh incorrectly handled the ChaCha20\ncipher. An attacker could possibly use this issue to cause libssh to\nuse partially initialized cypher content. This issue only affected Ubuntu\n24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04. (CVE-2025-5987)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.4","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.4","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.1","pocket":"security"}],"oracular":[{"name":"libssh","version":"0.10.6-3ubuntu1.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-3ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-3ubuntu1.1","pocket":"security"}],"plucky":[{"name":"libssh","version":"0.11.1-1ubuntu0.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.1-1ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.1-1ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2025-5351","CVE-2025-5372","CVE-2025-4877","CVE-2025-5318","CVE-2025-5987","CVE-2025-4878","CVE-2025-5449"]},{"id":"USN-7696-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2025-08-14T06:35:13.360351","description":"Ronald Crane discovered that libssh incorrectly handled certain base64\nconversions. An attacker could use this issue to cause libssh to crash,\nresulting in a denial of service, or possibly execute arbitrary code.\n(CVE-2025-4877)\n\nRonald Crane discovered that libssh incorrectly handled the\nprivatekey_from_file() function. An attacker could use this issue to cause\nlibssh to crash, resulting in a denial of service, or possibly execute\narbitrary code. (CVE-2025-4878)\n\nRonald Crane discovered that libssh incorrectly handled certain memory\noperations in the sftp server. An attacker could possibly use this issue\nto cause libssh to crash, resulting in a denial of service.\n(CVE-2025-5318)","is_hidden":false,"release_packages":{"bionic":[{"name":"libssh","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-dev","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-doc","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-4","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-dev","version":"0.8.0~20170825.94fa1e38-1ubuntu0.7+esm4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"libssh","version":"0.9.3-2ubuntu2.5+esm1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-dev","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-doc","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-4","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-dev","version":"0.9.3-2ubuntu2.5+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"libssh","version":"0.6.3-4.3ubuntu0.6+esm2","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-dev","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-doc","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-4","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"},{"name":"libssh-gcrypt-dev","version":"0.6.3-4.3ubuntu0.6+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2025-4877","CVE-2025-5318","CVE-2025-4878"]}]},{"id":"CVE-2025-6557","published":"2025-06-24T20:15:00","updated_at":"2025-06-25T19:33:26.028517+00:00","description":"\nInsufficient data validation in DevTools in Google Chrome on Windows prior\nto 138.0.7204.49 allowed a remote attacker who convinced a user to engage\nin specific UI gestures to execute arbitrary code via a crafted HTML page.\n(Chromium security severity: Low)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-6557","https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_24.html","https://issues.chromium.org/issues/406631048"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-6556","published":"2025-06-24T20:15:00","updated_at":"2025-06-27T06:11:19.723109+00:00","description":"\nInsufficient policy enforcement in Loader in Google Chrome prior to\n138.0.7204.49 allowed a remote attacker to bypass content security policy\nvia a crafted HTML page. (Chromium security severity: Low)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-6556","https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_24.html","https://issues.chromium.org/issues/40062462"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-6555","published":"2025-06-24T20:15:00","updated_at":"2025-06-27T06:11:19.723109+00:00","description":"\nUse after free in Animation in Google Chrome prior to 138.0.7204.49 allowed\na remote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: Medium)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-6555","https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_24.html","https://issues.chromium.org/issues/407328533"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-53021","published":"2025-06-24T20:15:00","updated_at":"2025-06-25T19:33:17.985988+00:00","description":"\nA session fixation vulnerability in Moodle 3.x through 3.11.18 allows\nunauthenticated attackers to hijack user sessions via the sesskey\nparameter. The sesskey can be obtained without authentication and reused\nwithin the OAuth2 login flow, resulting in the victim's session being\nlinked to the attacker's. Successful exploitation results in full account\ntakeover. According to the Moodle Releases page, \"Bug fixes for security\nissues in 3.11.x ended 11 December 2023.\" NOTE: This vulnerability only\naffects products that are no longer supported by the maintainer.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-53021","https://github.com/moodle/moodle/releases/tag/v3.11.18","https://moodledev.io/general/releases#moodle-311","https://rentry.co/moodle-oauth2-cve"],"bugs":[""],"patches":{"moodle":[]},"tags":{},"packages":[{"name":"moodle","source":"https://ubuntu.com/security/cve?package=moodle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=moodle","debian":"https://tracker.debian.org/pkg/moodle","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2025-6536","published":"2025-06-24T00:00:00","updated_at":"2026-09-11T06:56:54.769372+00:00","description":"\nA vulnerability has been found in Tarantool up to 3.3.1 and classified as\nproblematic. Affected by this vulnerability is the function tm_to_datetime\nin the library src/lib/core/datetime.c. The manipulation leads to reachable\nassertion. Attacking locally is a requirement. The exploit has been\ndisclosed to the public and may be used.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2025-6536","https://github.com/tarantool/tarantool/issues/11347","https://github.com/user-attachments/files/19613858/tarantool_crash.txt","https://vuldb.com/?ctiid.313663","https://vuldb.com/?id.313663","https://vuldb.com/?submit.597454"],"bugs":[""],"patches":{"tarantool":[]},"tags":{},"packages":[{"name":"tarantool","source":"https://ubuntu.com/security/cve?package=tarantool","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tarantool","debian":"https://tracker.debian.org/pkg/tarantool","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":21100,"limit":20,"total_results":79316}