{"cves":[{"id":"CVE-2026-78681","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:29.871294+00:00","description":"\nNLTK versions before 3.10.3 use xml.etree.ElementTree to parse XML in\nmultiple modules, which honors entity declarations in document DTDs.\nAttackers can craft XML payloads with nested entity declarations that\nexpand from hundreds of bytes to megabytes in memory, causing denial of\nservice.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-78681","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/78xxx/cve-2026-78681.json","https://github.com/nltk/nltk/security/advisories/ghsa-97qj-x29f-37w7","https://nvd.nist.gov/vuln/detail/cve-2026-78681","https://www.vulncheck.com/advisories/nltk-before-entity-expansion-dos-via-elementtree"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-78680","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:38.326851+00:00","description":"\nNLTK versions before 3.10.3 fail to use validated absolute paths when\ninvoking the Graphviz dot binary in dependencygraph.dot2img and\nAlignedSent._repr_svg_, allowing attackers to execute arbitrary code by\nplacing a malicious dot binary in the search path or current working\ndirectory. Attackers can exploit bare-name binary resolution on Windows via\nthe current working directory or on Unix-like systems via relative PATH\nentries to execute their binary instead of the legitimate Graphviz tool.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-78680","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/78xxx/cve-2026-78680.json","https://github.com/nltk/nltk/security/advisories/ghsa-6hwm-xvph-95vm","https://nvd.nist.gov/vuln/detail/cve-2026-78680","https://www.vulncheck.com/advisories/nltk-before-arbitrary-code-execution-via-graphviz-dot-binary"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-78679","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:44.879518+00:00","description":"\nGitPython before 3.1.59 contains an arbitrary file read vulnerability in\nTagReference.create() where a positional reference parameter bypasses the\nunsafe option guard. Attackers can supply a reference value like\n--file=<path> to read arbitrary files, with contents returned in the\nannotated tag message.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-78679","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/78xxx/cve-2026-78679.json","https://github.com/gitpython-developers/gitpython/security/advisories/ghsa-3wxw-xv34-2frg","https://nvd.nist.gov/vuln/detail/cve-2026-78679","https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-tagreference-create"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-78678","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:50.170209+00:00","description":"\nGitPython versions before 3.1.59 contain an incomplete denylist in the\nunsafe_git_revision_options guard that omits --contents and -S options,\nallowing attackers to read arbitrary files by passing these options to\nRepo.blame(). Attackers can supply revision values like\n--contents=/etc/passwd to leak file contents through the blame result\nreturned to the caller.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-78678","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/78xxx/cve-2026-78678.json","https://github.com/gitpython-developers/gitpython/security/advisories/ghsa-5xxx-qhh7-9287","https://nvd.nist.gov/vuln/detail/cve-2026-78678","https://www.vulncheck.com/advisories/gitpython-before-arbitrary-file-read-via-repo-blame"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-78677","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:29.871294+00:00","description":"\nGitPython before 3.1.59 omits --separate-git-dir from\nunsafe_git_clone_options, allowing attackers to create arbitrary git\ndirectories outside the intended clone destination. Attackers can pass a\nseparate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect\nrepository metadata to an attacker-controlled filesystem path, enabling\narbitrary directory creation and potential hook execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-78677","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/78xxx/cve-2026-78677.json","https://github.com/gitpython-developers/gitpython/security/advisories/ghsa-8mcc-hrx5-hvxc","https://nvd.nist.gov/vuln/detail/cve-2026-78677","https://www.vulncheck.com/advisories/gitpython-before-path-traversal-via-separate-git-dir"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-78675","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:44.879518+00:00","description":"\nGitPython before 3.1.59 fails to disable merge_includes when parsing\n.gitmodules, allowing attackers to disclose local file content by including\narbitrary file paths via [include] directives. Attackers can craft a\nmalicious .gitmodules file with include directives pointing to sensitive\nfiles; when repo.submodules is accessed, GitConfigParser raises\nMissingSectionHeaderError embedding the target file's first line verbatim\nin the exception message.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nminor issue as upstream suggests"}],"codename":null,"priority":"low","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-78675","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/78xxx/cve-2026-78675.json","https://github.com/gitpython-developers/gitpython/security/advisories/ghsa-7833-fr7j-v32q","https://nvd.nist.gov/vuln/detail/cve-2026-78675","https://www.vulncheck.com/advisories/gitpython-before-local-file-content-disclosure-via-gitmodules"],"bugs":[""],"patches":{},"tags":{},"packages":[],"notices_ids":[],"notices":[]},{"id":"CVE-2026-75803","published":"2026-08-25T00:00:00","updated_at":"2026-09-04T05:07:55.926622+00:00","description":"\nIssue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty\nciphertext can report success without verifying the supplied authentication\ntag when the operation is finalized by calling the EVP_Cipher() function.\nImpact summary: Applications calling EVP_Cipher() on an empty ciphertext\nand\nexpecting the call to check the AEAD tag may accept forged messages.\nCWE: CWE-354 (Improper Validation of Integrity Check Value)\nDescription: The EVP_Cipher() API call for AEAD ciphers behaves like a one\nshot encryption and decryption call. It also verifies the AEAD tag after\nthe\ndecryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers\nit skipped the AEAD tag verification when an empty ciphertext was passed to\nthe function. The callers of this function might believe that a successful\nreturn indicates a valid AEAD tag for these ciphers, even when that has not\ntruly been validated in this case.\nFIPS impact: no\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this\nCVE\nas the affected algorithms are not FIPS approved and thus not implemented\nin the FIPS module.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\n4.0, 3.6, 3.5, 3.4, and 3.0 are vulnerable\n\nWhile USN-8678-1 mentions that this CVE was fixes in Ubuntu\n26.04 LTS, it was unfortunately not. A subsequent USN will fix\nthis in 26.04 LTS."}],"codename":null,"priority":"low","cvss3":9.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":9.1,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-75803","https://ubuntu.com/security/notices/USN-8678-1","https://ubuntu.com/security/notices/USN-8678-3"],"bugs":[""],"patches":{"openssl":["upstream: https://github.com/openssl/openssl/commit/119ab9555dc62275bbd71f6f49529b1a44feba42","upstream: https://github.com/openssl/openssl/commit/2d17f2d7c0aa02e4e984dbf47d754d5d3defdf54","upstream: https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34","upstream: https://github.com/openssl/openssl/commit/e9fb43aee8654b492ed8a239d3f2bacf13bb9081"],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.29","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.5","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15+Fips1","component":null,"pocket":"fips-updates"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8678-1","USN-8678-3"],"notices":[{"id":"USN-8678-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-25T17:38:49.540843","description":"It was discovered that OpenSSL incorrectly handled the QUIC server incoming\nchannel queue. A remote attacker could possibly use this issue to cause\nOpenSSL to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\nIt was discovered that OpenSSL incorrectly handled signature algorithm\nselection when using Raw Public Keys. A remote attacker could possibly use\nthis issue to cause OpenSSL to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\nIt was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\nprocessing. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\nIt was discovered that OpenSSL incorrectly handled buffering of DTLS\nrecords for a future epoch. A remote attacker could possibly use this issue\nto cause OpenSSL to use excessive resources, leading to a denial of\nservice. (CVE-2026-54874)\n\nIt was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\nremote attacker could possibly use this issue to cause a heap buffer\noverflow, leading to a denial of service or arbitrary code execution.\n(CVE-2026-63072)\n\nIt was discovered that OpenSSL incorrectly validated the sender\ndistinguished name in CMP response messages. A remote attacker could\npossibly use this issue to cause OpenSSL to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\nIt was discovered that OpenSSL incorrectly limited the growth of an\ninternal certificate cache used during CMP operations. A remote attacker\ncould possibly use this issue to cause OpenSSL to use excessive resources,\nleading to a denial of service. (CVE-2026-63074)\n\nIt was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\nretention. A remote attacker could possibly use this issue to cause OpenSSL\nto use excessive resources, leading to a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\nIt was discovered that OpenSSL incorrectly handled CMP protection algorithm\nvalidation. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\nIt was discovered that OpenSSL incorrectly verified authentication tags\nwhen using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\ncould possibly use this issue to perform AEAD forgery attacks.\n(CVE-2026-75803)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.29","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-63076","CVE-2026-54874","CVE-2026-63075","CVE-2026-14456","CVE-2026-18798","CVE-2026-14457","CVE-2026-75803","CVE-2026-63073","CVE-2026-63074","CVE-2026-63072"]},{"id":"USN-8678-3","title":"OpenSSL vulnerability","summary":"USN-8678-1 contained an incomplete fix for Ubuntu 26.04 LTS.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-31T12:18:40.376022","description":"USN-8673-1 fixed vulnerabilities in OpenSSL. The update inadvertently left\nout the fix for CVE-2026-75803 in Ubuntu 26.04 LTS. This update fixes the\nproblem.\n\nWe apologize for the inconvenience.\n\nOriginal advisory details:\n\n It was discovered that OpenSSL incorrectly handled the QUIC server incoming\n channel queue. A remote attacker could possibly use this issue to cause\n OpenSSL to use excessive resources, leading to a denial of service. This\n issue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\n It was discovered that OpenSSL incorrectly handled signature algorithm\n selection when using Raw Public Keys. A remote attacker could possibly use\n this issue to cause OpenSSL to crash, resulting in a denial of service.\n This issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\n It was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\n processing. A remote attacker could possibly use this issue to cause\n OpenSSL to crash, resulting in a denial of service. This issue only\n affected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\n It was discovered that OpenSSL incorrectly handled buffering of DTLS\n records for a future epoch. A remote attacker could possibly use this issue\n to cause OpenSSL to use excessive resources, leading to a denial of\n service. (CVE-2026-54874)\n\n It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\n remote attacker could possibly use this issue to cause a heap buffer\n overflow, leading to a denial of service or arbitrary code execution.\n (CVE-2026-63072)\n\n It was discovered that OpenSSL incorrectly validated the sender\n distinguished name in CMP response messages. A remote attacker could\n possibly use this issue to cause OpenSSL to crash, resulting in a denial of\n service. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\n It was discovered that OpenSSL incorrectly limited the growth of an\n internal certificate cache used during CMP operations. A remote attacker\n could possibly use this issue to cause OpenSSL to use excessive resources,\n leading to a denial of service. (CVE-2026-63074)\n\n It was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\n retention. A remote attacker could possibly use this issue to cause OpenSSL\n to use excessive resources, leading to a denial of service. This issue only\n affected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\n It was discovered that OpenSSL incorrectly handled CMP protection algorithm\n validation. A remote attacker could possibly use this issue to cause\n OpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\n It was discovered that OpenSSL incorrectly verified authentication tags\n when using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\n could possibly use this issue to perform AEAD forgery attacks.\n (CVE-2026-75803)","is_hidden":false,"release_packages":{"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.5","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.5","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.5","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.5","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.5","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.5","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-75803"]}]},{"id":"CVE-2026-63076","published":"2026-08-25T00:00:00","updated_at":"2026-09-02T21:05:28.156375+00:00","description":"\nIssue summary: OpenSSL CMP password based protection verification only\nchecks whether the protectionAlg parameter was not NULL and not its\nASN.1 type, before treating it as a PBMParameter. A crafted message can\ncontain a parameter of a different type, which is then dereferenced as an\ninvalid pointer.\nImpact summary: A remote, unauthenticated attacker can crash an application\nacting as a CMP server that accepts PBM-protected messages, or a CMP client\ntalking to a malicious or intercepted CMP server, resulting in a Denial of\nService.\nCWE: CWE-476: NULL Pointer Dereference\nDescription: When verifying the password-based MAC protection of a CMP\nmessage, OpenSSL library reads the protectionAlg algorithm parameter with\nX509_ALGOR_get0(), which returns both the parameter type and its value\npointer. The value is then cast to an ASN1_STRING and treated as the\nexpected PBMParameter after only checking that pointer is not NULL. The\nparameter type returned by X509_ALGOR_get0() was never consulted.\nThis happens during protection verification, before any MAC is computed, so\nno knowledge of the PBM shared secret is required; the only precondition is\nthat PBM verification is reachable. On the server side this is reached from\nOSSL_CMP_SRV_process_request() for any application that stands up a CMP\nserver accepting PBM-protected messages, and on the client side from CMP\nresponse validation against a malicious or on-path (MITM) server. The\nreliable consequence is a denial of service; there is no memory disclosure,\nno controlled memory write, and no path to code execution. CMP is a\nspecialized feature that an application must explicitly enable.\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS modules\nare affected by this CVE.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\n4.0, 3.6, 3.5, 3.4, 3.0 are vulnerable"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63076","https://ubuntu.com/security/notices/USN-8678-1","https://ubuntu.com/security/notices/USN-8678-2"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.29","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.4","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15+Fips1","component":null,"pocket":"fips-updates"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8678-1"],"notices":[{"id":"USN-8678-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-25T17:38:49.540843","description":"It was discovered that OpenSSL incorrectly handled the QUIC server incoming\nchannel queue. A remote attacker could possibly use this issue to cause\nOpenSSL to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\nIt was discovered that OpenSSL incorrectly handled signature algorithm\nselection when using Raw Public Keys. A remote attacker could possibly use\nthis issue to cause OpenSSL to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\nIt was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\nprocessing. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\nIt was discovered that OpenSSL incorrectly handled buffering of DTLS\nrecords for a future epoch. A remote attacker could possibly use this issue\nto cause OpenSSL to use excessive resources, leading to a denial of\nservice. (CVE-2026-54874)\n\nIt was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\nremote attacker could possibly use this issue to cause a heap buffer\noverflow, leading to a denial of service or arbitrary code execution.\n(CVE-2026-63072)\n\nIt was discovered that OpenSSL incorrectly validated the sender\ndistinguished name in CMP response messages. A remote attacker could\npossibly use this issue to cause OpenSSL to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\nIt was discovered that OpenSSL incorrectly limited the growth of an\ninternal certificate cache used during CMP operations. A remote attacker\ncould possibly use this issue to cause OpenSSL to use excessive resources,\nleading to a denial of service. (CVE-2026-63074)\n\nIt was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\nretention. A remote attacker could possibly use this issue to cause OpenSSL\nto use excessive resources, leading to a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\nIt was discovered that OpenSSL incorrectly handled CMP protection algorithm\nvalidation. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\nIt was discovered that OpenSSL incorrectly verified authentication tags\nwhen using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\ncould possibly use this issue to perform AEAD forgery attacks.\n(CVE-2026-75803)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.29","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-63076","CVE-2026-54874","CVE-2026-63075","CVE-2026-14456","CVE-2026-18798","CVE-2026-14457","CVE-2026-75803","CVE-2026-63073","CVE-2026-63074","CVE-2026-63072"]}]},{"id":"CVE-2026-63075","published":"2026-08-25T00:00:00","updated_at":"2026-09-02T21:05:02.167454+00:00","description":"\nIssue summary: When OpenSSL processes QUIC traffic from a peer that\nrepeatedly\nsends ack-eliciting packets while not acknowledging ACK-only responses, the\nQUIC stack can retain ACK-only packet metadata for the lifetime of the\nconnection.\nImpact summary: A remote peer that can complete a QUIC handshake can\ncause connection-scoped memory growth which may lead to Denial of Service\nthrough memory exhaustion, especially with sustained traffic or many\nconcurrent\nQUIC connections.\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\nDescription: When the OpenSSL QUIC stack sends an ACK-only packet,\nthere is no requirement by the QUIC protocol that the peer will acknowledge\nthat ACK-only packet (i.e. it is itself not ack-eliciting). However, the\nOpenSSL\nimplementation stores the metadata about the ACK frames regardless.\nIn and of itself that's ok, but if a malicious peer establishes a\nconnection, and\nthen drives the connection such that ACK-only packets are forced from the\nOpenSSL implementation peer (i.e., by sending numerous PING frames),\nand then withholding any subsequent acks for ack-eliciting data, like\nlegitimate data, said malicious peer can force inappropriate memory growth\non the OpenSSL peer, potentially leading to a Denial of Service.\nThe fix is to ensure that we account for the transmission of the ACK-only\npacket in the packet histories high and low watermark without actually\nstoring\nthe ACK-only packet metadata itself.\nFIPS impact: no\nThe OpenSSL FIPS module is not affected as the QUIC code is\noutside the FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\n4.0, 3.6, 3.5, and 3.4 are vulnerable"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63075","https://ubuntu.com/security/notices/USN-8678-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.4","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8678-1"],"notices":[{"id":"USN-8678-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-25T17:38:49.540843","description":"It was discovered that OpenSSL incorrectly handled the QUIC server incoming\nchannel queue. A remote attacker could possibly use this issue to cause\nOpenSSL to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\nIt was discovered that OpenSSL incorrectly handled signature algorithm\nselection when using Raw Public Keys. A remote attacker could possibly use\nthis issue to cause OpenSSL to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\nIt was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\nprocessing. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\nIt was discovered that OpenSSL incorrectly handled buffering of DTLS\nrecords for a future epoch. A remote attacker could possibly use this issue\nto cause OpenSSL to use excessive resources, leading to a denial of\nservice. (CVE-2026-54874)\n\nIt was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\nremote attacker could possibly use this issue to cause a heap buffer\noverflow, leading to a denial of service or arbitrary code execution.\n(CVE-2026-63072)\n\nIt was discovered that OpenSSL incorrectly validated the sender\ndistinguished name in CMP response messages. A remote attacker could\npossibly use this issue to cause OpenSSL to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\nIt was discovered that OpenSSL incorrectly limited the growth of an\ninternal certificate cache used during CMP operations. A remote attacker\ncould possibly use this issue to cause OpenSSL to use excessive resources,\nleading to a denial of service. (CVE-2026-63074)\n\nIt was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\nretention. A remote attacker could possibly use this issue to cause OpenSSL\nto use excessive resources, leading to a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\nIt was discovered that OpenSSL incorrectly handled CMP protection algorithm\nvalidation. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\nIt was discovered that OpenSSL incorrectly verified authentication tags\nwhen using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\ncould possibly use this issue to perform AEAD forgery attacks.\n(CVE-2026-75803)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.29","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-63076","CVE-2026-54874","CVE-2026-63075","CVE-2026-14456","CVE-2026-18798","CVE-2026-14457","CVE-2026-75803","CVE-2026-63073","CVE-2026-63074","CVE-2026-63072"]}]},{"id":"CVE-2026-63074","published":"2026-08-25T00:00:00","updated_at":"2026-09-02T21:04:46.842262+00:00","description":"\nIssue summary: The OpenSSL Certificate Management Protocol (CMP) caches\nadditional certificates (extraCerts) sent in a CMP message, but never\nexpunges\nthem (for instance if they are invalid).  If a server reuses an\nOSSL_CMP_CTX\nfrequently, this cache of extraCerts may grow unboundedly, and a malicious\nclient may flood a CMP server with requests driving this growth.\nImpact summary: Users utilizing a CMP server that reuses a single\nOSSL_CMP_CTX\nfor the lifetime of a server process may observe unbounded memory growth in\nthe\nevent a malicious client repeatedly sends requests containing unique extra\ncertificates, which may lead to OOM conditions.\nCWE: CWE-770: Allocation of Resources Without Limits or Throttling\nDescription: If a remote user sends CMP messages to a server with a list of\nextraCerts and the message is rejected, the extraCerts from the message\nremains\nin the server contexts untrusted certificate stack.  This exposes servers\nwith\nlong lived ctx objects to Denial of Service attacks in which an attacker\nsends\nmessages intending to be rejected with a large list of additional\ncertificates\nrepeatedly, forcing the server to store them indefinitely.\nThe issue was fixed by removing the added extra certs if the message is\nrejected, using the same method as when the context is configured to not do\ncaching at all.\nFIPS impact: no\nAs the CMP code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\n4.0, 3.6, 3.5, 3.4, and 3.0 are vulnerable"}],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63074","https://ubuntu.com/security/notices/USN-8678-1","https://ubuntu.com/security/notices/USN-8678-2"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.29","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.4","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15+Fips1","component":null,"pocket":"fips-updates"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8678-1"],"notices":[{"id":"USN-8678-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-25T17:38:49.540843","description":"It was discovered that OpenSSL incorrectly handled the QUIC server incoming\nchannel queue. A remote attacker could possibly use this issue to cause\nOpenSSL to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\nIt was discovered that OpenSSL incorrectly handled signature algorithm\nselection when using Raw Public Keys. A remote attacker could possibly use\nthis issue to cause OpenSSL to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\nIt was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\nprocessing. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\nIt was discovered that OpenSSL incorrectly handled buffering of DTLS\nrecords for a future epoch. A remote attacker could possibly use this issue\nto cause OpenSSL to use excessive resources, leading to a denial of\nservice. (CVE-2026-54874)\n\nIt was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\nremote attacker could possibly use this issue to cause a heap buffer\noverflow, leading to a denial of service or arbitrary code execution.\n(CVE-2026-63072)\n\nIt was discovered that OpenSSL incorrectly validated the sender\ndistinguished name in CMP response messages. A remote attacker could\npossibly use this issue to cause OpenSSL to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\nIt was discovered that OpenSSL incorrectly limited the growth of an\ninternal certificate cache used during CMP operations. A remote attacker\ncould possibly use this issue to cause OpenSSL to use excessive resources,\nleading to a denial of service. (CVE-2026-63074)\n\nIt was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\nretention. A remote attacker could possibly use this issue to cause OpenSSL\nto use excessive resources, leading to a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\nIt was discovered that OpenSSL incorrectly handled CMP protection algorithm\nvalidation. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\nIt was discovered that OpenSSL incorrectly verified authentication tags\nwhen using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\ncould possibly use this issue to perform AEAD forgery attacks.\n(CVE-2026-75803)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.29","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-63076","CVE-2026-54874","CVE-2026-63075","CVE-2026-14456","CVE-2026-18798","CVE-2026-14457","CVE-2026-75803","CVE-2026-63073","CVE-2026-63074","CVE-2026-63072"]}]},{"id":"CVE-2026-63073","published":"2026-08-25T00:00:00","updated_at":"2026-09-02T21:04:07.771708+00:00","description":"\nIssue summary: OpenSSL CMP response validation passed an unexpected\nresponse\nsender distinguished name directly as the format string to\n`ERR_raise_data()`.\nImpact summary: A malicious or intercepted CMP endpoint can crash a CMP\nclient\nthat enforces an expected sender or uses a pinned server certificate whose\nsubject becomes the default expected sender.\nCWE: CWE-134 (Use of Externally-Controlled Format String)\nDescription: When validating a received CMP message,\nossl_cmp_msg_check_update()\nconverts the peer-supplied sender distinguished name with\nX509_NAME_oneline()\nand passes it directly as the format argument to ERR_raise_data(). Percent\ncharacters survive the conversion, so a sender DN such as \"CN=%s%n\" reaches\nBIO_vsnprintf() as an attacker-controlled format string with no matching\nvariadic\narguments. This path is only reached when the caller configures an expected\nsender or pins a server certificate, which is the normal configuration for\na\nCMP client validating server responses.\nSince the attacker controls the format string but none of the variadic\narguments, such specifiers as %s and %n dereference or write through\nunrelated\nstack contents and crash the client. The reliable consequence is a denial\nof\nservice, when the response comes from a malicious or intercepted CMP\nendpoint.\nThere is no controlled memory write, arbitrary-address read, or reliable\npath\nto remote code execution.\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the CMP protocol\nimplementation is outside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\n4.0, 3.6, 3.5, and 3.4 are vulnerable"}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63073","https://ubuntu.com/security/notices/USN-8678-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.4","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8678-1"],"notices":[{"id":"USN-8678-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-25T17:38:49.540843","description":"It was discovered that OpenSSL incorrectly handled the QUIC server incoming\nchannel queue. A remote attacker could possibly use this issue to cause\nOpenSSL to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\nIt was discovered that OpenSSL incorrectly handled signature algorithm\nselection when using Raw Public Keys. A remote attacker could possibly use\nthis issue to cause OpenSSL to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\nIt was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\nprocessing. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\nIt was discovered that OpenSSL incorrectly handled buffering of DTLS\nrecords for a future epoch. A remote attacker could possibly use this issue\nto cause OpenSSL to use excessive resources, leading to a denial of\nservice. (CVE-2026-54874)\n\nIt was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\nremote attacker could possibly use this issue to cause a heap buffer\noverflow, leading to a denial of service or arbitrary code execution.\n(CVE-2026-63072)\n\nIt was discovered that OpenSSL incorrectly validated the sender\ndistinguished name in CMP response messages. A remote attacker could\npossibly use this issue to cause OpenSSL to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\nIt was discovered that OpenSSL incorrectly limited the growth of an\ninternal certificate cache used during CMP operations. A remote attacker\ncould possibly use this issue to cause OpenSSL to use excessive resources,\nleading to a denial of service. (CVE-2026-63074)\n\nIt was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\nretention. A remote attacker could possibly use this issue to cause OpenSSL\nto use excessive resources, leading to a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\nIt was discovered that OpenSSL incorrectly handled CMP protection algorithm\nvalidation. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\nIt was discovered that OpenSSL incorrectly verified authentication tags\nwhen using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\ncould possibly use this issue to perform AEAD forgery attacks.\n(CVE-2026-75803)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.29","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-63076","CVE-2026-54874","CVE-2026-63075","CVE-2026-14456","CVE-2026-18798","CVE-2026-14457","CVE-2026-75803","CVE-2026-63073","CVE-2026-63074","CVE-2026-63072"]}]},{"id":"CVE-2026-63072","published":"2026-08-25T00:00:00","updated_at":"2026-09-02T21:06:17.590070+00:00","description":"\nIssue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer\nbased\non querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive\ncan write and cleanse more bytes than that query reports, causing an 8-byte\nout-of-bounds heap write.\nImpact summary: An attacker who supplies a crafted CMS message can trigger\na\ndeterministic 8-byte out-of-bounds heap write when the victim decrypts it\nwith CMS_decrypt(), corrupting the heap and typically resulting in a Denial\nof Service.\nCWE: CWE-787: Out-of-bounds Write\nDescription: The key-wrap OID is potentially attacker-controlled on the\nwire.\nCMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers.\nAn attacker can take a legitimate message and change a single OID byte to\nselect the padded variant while leaving the message otherwise valid. Since\nthe unwrap key is derived from the recipient's private operation (ECDH key\nagreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot\npass, and the decryption fails with integrity failure.\nThe write is a fixed-size (8-byte), fixed-value (zero) heap overflow\nimmediately past the allocation, requires no special configuration, and is\nreachable from the public CMS_decrypt() function. The consequence is\na heap corruption leading to a Denial of Service. The fix in the CMS code\nsizes the unwrap output buffer for the worst case so a failed unwrap cannot\nwrite past the allocation.\nFIPS impact: no\nAs the CMS code lives outside the FIPS module boundary, no FIPS\nmodules are affected by this CVE.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\n4.0, 3.6, 3.5, 3.4, 3.0, and 1.1.1 are vulnerable"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63072","https://ubuntu.com/security/notices/USN-8678-1","https://ubuntu.com/security/notices/USN-8678-2"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.1.1-1ubuntu2.1~18.04.23+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.1.1f-1ubuntu2.24+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"1.0.1f-1ubuntu2.27+esm16","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.0.2g-1ubuntu4.20+esm18","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.29","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.4","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15+Fips1","component":null,"pocket":"fips-updates"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2n-1ubuntu5.13+esm6","component":null,"pocket":"esm-infra"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8678-1","USN-8678-2"],"notices":[{"id":"USN-8678-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-25T17:38:49.540843","description":"It was discovered that OpenSSL incorrectly handled the QUIC server incoming\nchannel queue. A remote attacker could possibly use this issue to cause\nOpenSSL to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\nIt was discovered that OpenSSL incorrectly handled signature algorithm\nselection when using Raw Public Keys. A remote attacker could possibly use\nthis issue to cause OpenSSL to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\nIt was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\nprocessing. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\nIt was discovered that OpenSSL incorrectly handled buffering of DTLS\nrecords for a future epoch. A remote attacker could possibly use this issue\nto cause OpenSSL to use excessive resources, leading to a denial of\nservice. (CVE-2026-54874)\n\nIt was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\nremote attacker could possibly use this issue to cause a heap buffer\noverflow, leading to a denial of service or arbitrary code execution.\n(CVE-2026-63072)\n\nIt was discovered that OpenSSL incorrectly validated the sender\ndistinguished name in CMP response messages. A remote attacker could\npossibly use this issue to cause OpenSSL to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\nIt was discovered that OpenSSL incorrectly limited the growth of an\ninternal certificate cache used during CMP operations. A remote attacker\ncould possibly use this issue to cause OpenSSL to use excessive resources,\nleading to a denial of service. (CVE-2026-63074)\n\nIt was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\nretention. A remote attacker could possibly use this issue to cause OpenSSL\nto use excessive resources, leading to a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\nIt was discovered that OpenSSL incorrectly handled CMP protection algorithm\nvalidation. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\nIt was discovered that OpenSSL incorrectly verified authentication tags\nwhen using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\ncould possibly use this issue to perform AEAD forgery attacks.\n(CVE-2026-75803)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.29","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-63076","CVE-2026-54874","CVE-2026-63075","CVE-2026-14456","CVE-2026-18798","CVE-2026-14457","CVE-2026-75803","CVE-2026-63073","CVE-2026-63074","CVE-2026-63072"]},{"id":"USN-8678-2","title":"OpenSSL, OpenSSL 1.0 vulnerabilities","summary":"Several security issues were fixed in OpenSSL and OpenSSL 1.0.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-25T18:15:33.443535","description":"USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the\ncorresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,\nUbuntu 16.04 LTS, and Ubuntu 18.04 LTS.\n\nIn addition, this update also fixes the following issues that were\nnot previously addressed in those releases:\n\nIt was discovered that OpenSSL incorrectly handled TLS handshake\nmessage buffering. A remote attacker could possibly use this issue to\ncause OpenSSL to consume excessive memory, leading to a denial of\nservice. (LP: #2161371)\n\nIt was discovered that OpenSSL incorrectly handled session cache\nmanagement when processing TLSv1.3 sessions. A remote attacker could\npossibly use this issue to cause OpenSSL to consume excessive memory,\nleading to a denial of service. This issue only affected OpenSSL 1.1.1\non Ubuntu 18.04 LTS. (CVE-2024-2511)\n\nIt was discovered that OpenSSL incorrectly handled the SSL_select_next_proto\nfunction when called with an empty client protocol list. A remote attacker\ncould possibly use this issue to cause OpenSSL to disclose private memory\ncontents to the peer, leading to a loss of confidentiality. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-5535)\n\nOriginal advisory details:\n\n It was discovered that OpenSSL incorrectly handled buffering of DTLS\n records for a future epoch. A remote attacker could possibly use this issue\n to cause OpenSSL to use excessive resources, leading to a denial of\n service. (CVE-2026-54874)\n\n It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\n remote attacker could possibly use this issue to cause a heap buffer\n overflow, leading to a denial of service or arbitrary code execution.\n (CVE-2026-63072)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm6","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0-dev","version":"1.0.2n-1ubuntu5.13+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0.0","version":"1.0.2n-1ubuntu5.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm5","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1f-1ubuntu2.24+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1f-1ubuntu2.24+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1f-1ubuntu2.24+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm16","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.1f-1ubuntu2.27+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.1f-1ubuntu2.27+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.1f-1ubuntu2.27+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm18","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.2g-1ubuntu4.20+esm18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.2g-1ubuntu4.20+esm18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.2g-1ubuntu4.20+esm18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-54874","CVE-2024-2511","CVE-2024-5535","CVE-2026-63072"]}]},{"id":"CVE-2026-59183","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:29.871294+00:00","description":"\nOpenEXR is the reference implementation and specification for the EXR image\nformat, widely used in the motion picture industry. In versions 3.1.0\nthrough 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t\nmultiplication in OpenEXRCore's unpack_sample_table() can overflow while\ndecoding a crafted deep tiled EXR file, producing an invalid pointer that\nleads to a read from an unmapped memory address and a crash. Because the\noverflow occurs in the standard decoding path (exr_decoding_run), any\napplication that decodes deep tiled EXR files is affected. This issue is\nfixed in versions 3.2.11, 3.3.13, and 3.4.14.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59183","https://github.com/academysoftwarefoundation/openexr/commit/5e55a64ad1f119a8166542f4b6e034c31b7e043a","https://github.com/academysoftwarefoundation/openexr/commit/a6cf183725b5665ac3fdbec640125fba5ee1ab39","https://github.com/academysoftwarefoundation/openexr/commit/e2adb5be3bbc3a1f82f2bc06cc9699995a99a607","https://github.com/academysoftwarefoundation/openexr/security/advisories/ghsa-rqp5-pmwm-wj6x","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/59xxx/cve-2026-59183.json","https://nvd.nist.gov/vuln/detail/cve-2026-59183"],"bugs":[""],"patches":{"openexr":[]},"tags":{},"packages":[{"name":"openexr","source":"https://ubuntu.com/security/cve?package=openexr","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openexr","debian":"https://tracker.debian.org/pkg/openexr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55373","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:38.326851+00:00","description":"\nOpenEXR is the reference implementation and specification for the EXR image\nformat, widely used in the motion picture industry. Versions prior to\n3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in\nSampleCountChannel. The helper roundListSizeUp() rounds a sample-list size\nup to the next power of two using repeated unsigned left shifts, which\nterminates for normal values but fails for UINT_MAX: the sequence reaches\n0x80000000, and the next left shift wraps the 32-bit value to 0. Because 0\nremains less than UINT_MAX, the loop never progresses and never exits. The\nbug is reachable through public OpenEXRUtil APIs, either by editing the\nsample-count buffer through SampleCountChannel::Edit (whose destructor\ncalls endEdit()) or by calling SampleCountChannel::set(x, y, UINT_MAX) on a\nvalid pixel. This issue has been fixed in versions 3.2.10, 3.3.12, and\n3.4.13.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55373","https://github.com/academysoftwarefoundation/openexr/security/advisories/ghsa-mff9-68x3-h8rh","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/55xxx/cve-2026-55373.json","https://nvd.nist.gov/vuln/detail/cve-2026-55373"],"bugs":[""],"patches":{"openexr":[]},"tags":{},"packages":[{"name":"openexr","source":"https://ubuntu.com/security/cve?package=openexr","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openexr","debian":"https://tracker.debian.org/pkg/openexr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55371","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:50.170209+00:00","description":"\nOpenEXR is the reference implementation and specification for the EXR\nhigh-dynamic-range image file format, widely used in the motion picture\nindustry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference\nin the OpenEXRCore function exr_attr_set_bytes(). The public setter\nvalidates the top-level exr_attr_bytes_t value pointer but does not verify\nthat the nested type_hint pointer is non-NULL when hint_length is greater\nthan zero. When a caller supplies a positive hint_length together with a\nNULL type_hint, exr_attr_bytes_create() allocates a destination type-hint\nbuffer and then copies from the NULL source pointer, causing a\ndeterministic crash. The flaw is reachable through the public OpenEXRCore C\nAPI and results in a denial of service. The issue is fixed in version\n3.4.13.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55371","https://github.com/academysoftwarefoundation/openexr/security/advisories/ghsa-xx72-f24p-cf6r","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/55xxx/cve-2026-55371.json","https://nvd.nist.gov/vuln/detail/cve-2026-55371"],"bugs":[""],"patches":{"openexr":[]},"tags":{},"packages":[{"name":"openexr","source":"https://ubuntu.com/security/cve?package=openexr","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openexr","debian":"https://tracker.debian.org/pkg/openexr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55059","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:38.326851+00:00","description":"\nOpenEXR is the reference implementation and specification for the EXR image\nformat, widely used in the motion picture industry. Versions prior to\n3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in\nImf_4_0::SampleCountChannel::set(int r, unsigned int newNumSamples[]). The\nrow-based sample-count setter computes the target Y coordinate with\ndataWindow.min.x instead of dataWindow.min.y. For a valid deep image data\nwindow where min.x != min.y, a valid row index can be translated into an\ninvalid Y coordinate, causing writes before the allocated _numSamples\nbuffer. The vulnerability is reachable through the public OpenEXRUtil\nDeepImage API and can lead to heap corruption and process crashes. This\nissue has been fixed in versions 3.2.10, 3.3.12 and 3.4.13.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55059","https://github.com/academysoftwarefoundation/openexr/security/advisories/ghsa-54cp-3rq6-7mq8","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/55xxx/cve-2026-55059.json","https://nvd.nist.gov/vuln/detail/cve-2026-55059"],"bugs":[""],"patches":{"openexr":[]},"tags":{},"packages":[{"name":"openexr","source":"https://ubuntu.com/security/cve?package=openexr","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openexr","debian":"https://tracker.debian.org/pkg/openexr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54920","published":"2026-08-25T00:00:00","updated_at":"2026-08-26T14:18:38.326851+00:00","description":"\nOpenEXR is the reference implementation and specification for the EXR image\nformat, widely used in the motion picture industry. In versions 3.4.0\nthrough 3.4.12, a reachable assertion failure in the HTJ2K decode path\nallows a crafted HTJ2K-compressed EXR file to cause an unconditional\nprocess abort in any application that calls exr_start_read() on untrusted\ninput, resulting in denial of service. The crash is triggered by a QCD\nmarker whose lower five bits are zero, which OpenEXR passes into the\nvendored OpenJPH library while constructing the codestream and evaluating\nits quantization delta parameters. OpenJPH uses an assertion rather than a\nrecoverable error to validate those bits, so any invalid value calls\nabort() directly and cannot be intercepted by surrounding error handling, a\nproblem compounded by OpenEXR wrapping only its internal HT header parser\nin error handling while leaving the later codestream read and construction\ncalls unprotected. This issue has been resolved in version 3.4.13.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":0.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":0.0,"baseSeverity":"NONE"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54920","https://github.com/academysoftwarefoundation/openexr/security/advisories/ghsa-fp75-87pr-8329","https://github.com/cveproject/cvelistv5/tree/main/cves/2026/54xxx/cve-2026-54920.json","https://nvd.nist.gov/vuln/detail/cve-2026-54920"],"bugs":[""],"patches":{"openexr":[]},"tags":{},"packages":[{"name":"openexr","source":"https://ubuntu.com/security/cve?package=openexr","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openexr","debian":"https://tracker.debian.org/pkg/openexr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54874","published":"2026-08-25T00:00:00","updated_at":"2026-09-02T21:04:23.398185+00:00","description":"\nIssue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\nFIPS impact: no\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\n4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54874","https://ubuntu.com/security/notices/USN-8678-1","https://ubuntu.com/security/notices/USN-8678-2"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"bionic","status":"released","description":"1.1.1-1ubuntu2.1~18.04.23+esm10","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"1.1.1f-1ubuntu2.24+esm5","component":null,"pocket":"esm-infra"},{"release_codename":"trusty","status":"released","description":"1.0.1f-1ubuntu2.27+esm16","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"1.0.2g-1ubuntu4.20+esm18","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.29","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.4","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.13-0ubuntu3.15+Fips1","component":null,"pocket":"fips-updates"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.0.2n-1ubuntu5.13+esm6","component":null,"pocket":"esm-infra"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8678-1","USN-8678-2"],"notices":[{"id":"USN-8678-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-25T17:38:49.540843","description":"It was discovered that OpenSSL incorrectly handled the QUIC server incoming\nchannel queue. A remote attacker could possibly use this issue to cause\nOpenSSL to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\nIt was discovered that OpenSSL incorrectly handled signature algorithm\nselection when using Raw Public Keys. A remote attacker could possibly use\nthis issue to cause OpenSSL to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\nIt was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\nprocessing. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\nIt was discovered that OpenSSL incorrectly handled buffering of DTLS\nrecords for a future epoch. A remote attacker could possibly use this issue\nto cause OpenSSL to use excessive resources, leading to a denial of\nservice. (CVE-2026-54874)\n\nIt was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\nremote attacker could possibly use this issue to cause a heap buffer\noverflow, leading to a denial of service or arbitrary code execution.\n(CVE-2026-63072)\n\nIt was discovered that OpenSSL incorrectly validated the sender\ndistinguished name in CMP response messages. A remote attacker could\npossibly use this issue to cause OpenSSL to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\nIt was discovered that OpenSSL incorrectly limited the growth of an\ninternal certificate cache used during CMP operations. A remote attacker\ncould possibly use this issue to cause OpenSSL to use excessive resources,\nleading to a denial of service. (CVE-2026-63074)\n\nIt was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\nretention. A remote attacker could possibly use this issue to cause OpenSSL\nto use excessive resources, leading to a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\nIt was discovered that OpenSSL incorrectly handled CMP protection algorithm\nvalidation. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\nIt was discovered that OpenSSL incorrectly verified authentication tags\nwhen using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\ncould possibly use this issue to perform AEAD forgery attacks.\n(CVE-2026-75803)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.29","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-63076","CVE-2026-54874","CVE-2026-63075","CVE-2026-14456","CVE-2026-18798","CVE-2026-14457","CVE-2026-75803","CVE-2026-63073","CVE-2026-63074","CVE-2026-63072"]},{"id":"USN-8678-2","title":"OpenSSL, OpenSSL 1.0 vulnerabilities","summary":"Several security issues were fixed in OpenSSL and OpenSSL 1.0.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-25T18:15:33.443535","description":"USN-8678-1 fixed vulnerabilities in OpenSSL. This update provides the\ncorresponding fix for OpenSSL and OpenSSL 1.0 on Ubuntu 14.04 LTS,\nUbuntu 16.04 LTS, and Ubuntu 18.04 LTS.\n\nIn addition, this update also fixes the following issues that were\nnot previously addressed in those releases:\n\nIt was discovered that OpenSSL incorrectly handled TLS handshake\nmessage buffering. A remote attacker could possibly use this issue to\ncause OpenSSL to consume excessive memory, leading to a denial of\nservice. (LP: #2161371)\n\nIt was discovered that OpenSSL incorrectly handled session cache\nmanagement when processing TLSv1.3 sessions. A remote attacker could\npossibly use this issue to cause OpenSSL to consume excessive memory,\nleading to a denial of service. This issue only affected OpenSSL 1.1.1\non Ubuntu 18.04 LTS. (CVE-2024-2511)\n\nIt was discovered that OpenSSL incorrectly handled the SSL_select_next_proto\nfunction when called with an empty client protocol list. A remote attacker\ncould possibly use this issue to cause OpenSSL to disclose private memory\ncontents to the peer, leading to a loss of confidentiality. This issue\nonly affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-5535)\n\nOriginal advisory details:\n\n It was discovered that OpenSSL incorrectly handled buffering of DTLS\n records for a future epoch. A remote attacker could possibly use this issue\n to cause OpenSSL to use excessive resources, leading to a denial of\n service. (CVE-2026-54874)\n\n It was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\n remote attacker could possibly use this issue to cause a heap buffer\n overflow, leading to a denial of service or arbitrary code execution.\n (CVE-2026-63072)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm6","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0-dev","version":"1.0.2n-1ubuntu5.13+esm6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.0.0","version":"1.0.2n-1ubuntu5.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1-1ubuntu2.1~18.04.23+esm10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl1.0","version":"1.0.2n-1ubuntu5.13+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl1.0","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm5","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.1.1f-1ubuntu2.24+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl-doc","version":"1.1.1f-1ubuntu2.24+esm5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"libssl1.1","version":"1.1.1f-1ubuntu2.24+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"},{"name":"openssl","version":"1.1.1f-1ubuntu2.24+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm16","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.1f-1ubuntu2.27+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.1f-1ubuntu2.27+esm16","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.1f-1ubuntu2.27+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.1f-1ubuntu2.27+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm18","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"1.0.2g-1ubuntu4.20+esm18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl-doc","version":"1.0.2g-1ubuntu4.20+esm18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libssl1.0.0","version":"1.0.2g-1ubuntu4.20+esm18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"},{"name":"openssl","version":"1.0.2g-1ubuntu4.20+esm18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-54874","CVE-2024-2511","CVE-2024-5535","CVE-2026-63072"]}]},{"id":"CVE-2026-18798","published":"2026-08-25T00:00:00","updated_at":"2026-09-02T21:02:59.954562+00:00","description":"\nIssue summary: QUIC server may double free QRX (QUIC record layer RX)\nobject\nwhen channel creation fails for initial packet.\nImpact summary: Double free leads to heap corruption, which typically\nresults in\ntermination of QUIC server process, leading to Denial of Service. There is\nso\nfar no evidence that this double free is exploitable for remote code\nexecution,\nthus it is considered highly improbable.\nCWE: CWE-415: Double Free\nDescription: In order to validate initial packet, OpenSSL QUIC stack\ndefault\npacket handler (port_default_packet_handler()) creates a so-called QRX\nobject.\nIf the initial packet validates successfully with QRX object, the default\npacket\nhandler proceeds to channel (connection object) creation. The QRX object\nused\nfor packet validation is passed to port_bind_channel(), so it becomes part\nof\nthe newly created connection. If port_bind_channel() fails, then it also\nfrees\nthe QRX object. Once port_bind_channel() returns, the\nport_default_packet_handler()\ndetects the failure and proceeds to the error branch, where the same QRX\nobject is\nfreed for the second time.\nThe failure in port_bind_channel() function can be induced with a\nrelatively\nlow effort by a malformed (non RFC 9000 compliant) INITIAL packet. If the\npacket\ncarries DCID (destination connection ID) which is shorter than 8 bytes,\nthen\nport_bind_channel() jumps to the error path after\nossl_quic_lcidm_enrol_odcid()\ndetects that the DCID has invalid length.\nFIPS impact: no\nThe FIPS module is not affected, as the QUIC implementation is outside of\nthe OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\n4.0, 3.6, and 3.5 are vulnerable"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-18798","https://ubuntu.com/security/notices/USN-8678-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.4","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.5+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.5+ only","component":null,"pocket":"fips-updates"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.5+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8678-1"],"notices":[{"id":"USN-8678-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-25T17:38:49.540843","description":"It was discovered that OpenSSL incorrectly handled the QUIC server incoming\nchannel queue. A remote attacker could possibly use this issue to cause\nOpenSSL to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\nIt was discovered that OpenSSL incorrectly handled signature algorithm\nselection when using Raw Public Keys. A remote attacker could possibly use\nthis issue to cause OpenSSL to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\nIt was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\nprocessing. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\nIt was discovered that OpenSSL incorrectly handled buffering of DTLS\nrecords for a future epoch. A remote attacker could possibly use this issue\nto cause OpenSSL to use excessive resources, leading to a denial of\nservice. (CVE-2026-54874)\n\nIt was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\nremote attacker could possibly use this issue to cause a heap buffer\noverflow, leading to a denial of service or arbitrary code execution.\n(CVE-2026-63072)\n\nIt was discovered that OpenSSL incorrectly validated the sender\ndistinguished name in CMP response messages. A remote attacker could\npossibly use this issue to cause OpenSSL to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\nIt was discovered that OpenSSL incorrectly limited the growth of an\ninternal certificate cache used during CMP operations. A remote attacker\ncould possibly use this issue to cause OpenSSL to use excessive resources,\nleading to a denial of service. (CVE-2026-63074)\n\nIt was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\nretention. A remote attacker could possibly use this issue to cause OpenSSL\nto use excessive resources, leading to a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\nIt was discovered that OpenSSL incorrectly handled CMP protection algorithm\nvalidation. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\nIt was discovered that OpenSSL incorrectly verified authentication tags\nwhen using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\ncould possibly use this issue to perform AEAD forgery attacks.\n(CVE-2026-75803)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.29","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-63076","CVE-2026-54874","CVE-2026-63075","CVE-2026-14456","CVE-2026-18798","CVE-2026-14457","CVE-2026-75803","CVE-2026-63073","CVE-2026-63074","CVE-2026-63072"]}]},{"id":"CVE-2026-14457","published":"2026-08-25T00:00:00","updated_at":"2026-09-02T21:03:46.573248+00:00","description":"\nIssue summary: In a server or client configuration with RFC7250 Raw Public\nKeys (RPKs)\nenabled, and only the private key (with no associated certificate)\nconfigured locally,\na NULL pointer dereference may occur when the remote peer solicits raw\npublic keys and\nalso sends the typically omitted \"signature_algorithms_cert\" TLS extension.\nImpact summary: The impact is limited to a possible Denial of Service as a\nresult of\nan application abort, no data disclosure or remote command execution are\npossible.\nCWE: CWE-476: NULL Pointer Dereference\nDescription: While a passing comment in sample code in the documentation\nsuggests\nthat key-only RPK configurations are supported, the best-practice RPK\nconfiguration\nis to always configure a corresponding certificate (possibly self-signed or\nsigned by any convenient CA).\nWhen the private key is configured along with a matching certificate, the\n\"signature_algorithms_cert\" extension is handled reliably even without the\nfix, and peer clients or servers that don't support raw public keys may be\nable to complete a TLS connection by pinning or verifying the corresponding\ncertificate or its public key.\nDeployments that prefer to configure just a private key with no certificate\nneed to upgrade to an updated release as noted below.\nFIPS impact: no\nNo FIPS modules are affected by this issue, as the SSL protocol\nimplementation\nis outside the OpenSSL FIPS module boundary.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nOpenSSL developers have rated this low severity"},{"author":"mdeslaur","note":"edk2 in jammy embeds OpenSSL 1.1.1j\nedk2 in noble embeds OpenSSL 3.0.9\nedk2 in plucky embeds OpenSSL 3.4.0\nedk2 in questing embeds OpenSSL 3.4.0\nedk2 in resolute embeds OpenSSL 3.5.1\nedk2 in stonking embeds OpenSSL 3.5.1\nnodejs in jammy embeds OpenSSL 1.1.1m\n4.0, 3.6, 3.5, and 3.4 are vulnerable"}],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14457","https://ubuntu.com/security/notices/USN-8678-1"],"bugs":[""],"patches":{"openssl":[],"openssl-fips":[],"openssl1.0":[],"nodejs":[],"edk2":[],"edk2-hwe":[]},"tags":{},"packages":[{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"trusty","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.5.5-1ubuntu3.4","component":null,"pocket":"security"}]},{"name":"openssl-fips","source":"https://ubuntu.com/security/cve?package=openssl-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl-fips","debian":"https://tracker.debian.org/pkg/openssl-fips","statuses":[{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"fips-updates"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"xenial","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.4+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"edk2-hwe","source":"https://ubuntu.com/security/cve?package=edk2-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=edk2-hwe","debian":"https://tracker.debian.org/pkg/edk2-hwe","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8678-1"],"notices":[{"id":"USN-8678-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.","references":[],"published":"2026-08-25T17:38:49.540843","description":"It was discovered that OpenSSL incorrectly handled the QUIC server incoming\nchannel queue. A remote attacker could possibly use this issue to cause\nOpenSSL to use excessive resources, leading to a denial of service. This\nissue only affected Ubuntu 26.04 LTS. (CVE-2026-14456)\n\nIt was discovered that OpenSSL incorrectly handled signature algorithm\nselection when using Raw Public Keys. A remote attacker could possibly use\nthis issue to cause OpenSSL to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 26.04 LTS. (CVE-2026-14457)\n\nIt was discovered that OpenSSL incorrectly handled QUIC INITIAL packet\nprocessing. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-18798)\n\nIt was discovered that OpenSSL incorrectly handled buffering of DTLS\nrecords for a future epoch. A remote attacker could possibly use this issue\nto cause OpenSSL to use excessive resources, leading to a denial of\nservice. (CVE-2026-54874)\n\nIt was discovered that OpenSSL incorrectly handled CMS key unwrapping. A\nremote attacker could possibly use this issue to cause a heap buffer\noverflow, leading to a denial of service or arbitrary code execution.\n(CVE-2026-63072)\n\nIt was discovered that OpenSSL incorrectly validated the sender\ndistinguished name in CMP response messages. A remote attacker could\npossibly use this issue to cause OpenSSL to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-63073)\n\nIt was discovered that OpenSSL incorrectly limited the growth of an\ninternal certificate cache used during CMP operations. A remote attacker\ncould possibly use this issue to cause OpenSSL to use excessive resources,\nleading to a denial of service. (CVE-2026-63074)\n\nIt was discovered that OpenSSL incorrectly handled QUIC ACK-only packet\nretention. A remote attacker could possibly use this issue to cause OpenSSL\nto use excessive resources, leading to a denial of service. This issue only\naffected Ubuntu 26.04 LTS. (CVE-2026-63075)\n\nIt was discovered that OpenSSL incorrectly handled CMP protection algorithm\nvalidation. A remote attacker could possibly use this issue to cause\nOpenSSL to crash, resulting in a denial of service. (CVE-2026-63076)\n\nIt was discovered that OpenSSL incorrectly verified authentication tags\nwhen using certain AEAD ciphers via the EVP_Cipher() interface. An attacker\ncould possibly use this issue to perform AEAD forgery attacks.\n(CVE-2026-75803)","is_hidden":false,"release_packages":{"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.29","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.29","pocket":"security"}],"noble":[{"name":"openssl","version":"3.0.13-0ubuntu3.15","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl-doc","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"libssl3t64","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"},{"name":"openssl","version":"3.0.13-0ubuntu3.15","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.13-0ubuntu3.15","pocket":"security"}],"resolute":[{"name":"openssl","version":"3.5.5-1ubuntu3.4","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl-doc","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"libssl3t64","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"},{"name":"openssl-provider-legacy","version":"3.5.5-1ubuntu3.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.5.5-1ubuntu3.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-63076","CVE-2026-54874","CVE-2026-63075","CVE-2026-14456","CVE-2026-18798","CVE-2026-14457","CVE-2026-75803","CVE-2026-63073","CVE-2026-63074","CVE-2026-63072"]}]}],"offset":3100,"limit":20,"total_results":79316}