{"cves":[{"id":"CVE-2024-23263","published":"2024-03-08T02:15:00","updated_at":"2026-09-17T00:42:19.571753+00:00","description":"\nA logic issue was addressed with improved validation. This issue is fixed\nin Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4,\nmacOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing\nmaliciously crafted web content may prevent Content Security Policy from\nbeing enforced.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\nfocal and earlier. Marking as ignored."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2024-0002.html","https://www.cve.org/CVERecord?id=CVE-2024-23263","https://ubuntu.com/security/notices/USN-6732-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.44.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.44.0-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"2.44.0-0ubuntu0.23.10.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.44.0-2","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6732-1"],"notices":[{"id":"USN-6732-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2024-04-15T16:29:45.953212","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.\n","is_hidden":false,"release_packages":{"jammy":[{"name":"webkit2gtk","version":"2.44.0-0ubuntu0.22.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"}],"mantic":[{"name":"webkit2gtk","version":"2.44.0-0ubuntu0.23.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2024-23254","CVE-2024-23280","CVE-2024-23284","CVE-2023-42843","CVE-2024-23263","CVE-2023-42950","CVE-2023-42956","CVE-2024-23252"]}]},{"id":"CVE-2024-23254","published":"2024-03-08T02:15:00","updated_at":"2026-09-17T00:41:11.261448+00:00","description":"\nThe issue was addressed with improved UI handling. This issue is fixed in\nSafari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4,\nvisionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data\ncross-origin.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\nfocal and earlier. Marking as ignored."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2024-0002.html","https://www.cve.org/CVERecord?id=CVE-2024-23254","https://ubuntu.com/security/notices/USN-6732-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.44.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.44.0-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"2.44.0-0ubuntu0.23.10.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.44.0-2","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6732-1"],"notices":[{"id":"USN-6732-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2024-04-15T16:29:45.953212","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.\n","is_hidden":false,"release_packages":{"jammy":[{"name":"webkit2gtk","version":"2.44.0-0ubuntu0.22.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"}],"mantic":[{"name":"webkit2gtk","version":"2.44.0-0ubuntu0.23.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2024-23254","CVE-2024-23280","CVE-2024-23284","CVE-2023-42843","CVE-2024-23263","CVE-2023-42950","CVE-2023-42956","CVE-2024-23252"]}]},{"id":"CVE-2024-23252","published":"2024-03-08T02:15:00","updated_at":"2025-08-04T19:53:51.235397+00:00","description":"\nRejected reason: This CVE ID has been rejected or withdrawn by its CVE\nNumbering Authority.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\nfocal and earlier. Marking as ignored."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://webkitgtk.org/security/WSA-2024-0002.html","https://www.cve.org/CVERecord?id=CVE-2024-23252","https://ubuntu.com/security/notices/USN-6732-1"],"bugs":[""],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was not-affected","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.44.0","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"2.44.0-0ubuntu0.22.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"2.44.0-0ubuntu0.23.10.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.44.0-2","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6732-1"],"notices":[{"id":"USN-6732-1","title":"WebKitGTK vulnerabilities","summary":"Several security issues were fixed in WebKitGTK.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2024-04-15T16:29:45.953212","description":"Several security issues were discovered in the WebKitGTK Web and JavaScript\nengines. If a user were tricked into viewing a malicious website, a remote\nattacker could exploit a variety of issues related to web browser security,\nincluding cross-site scripting attacks, denial of service attacks, and\narbitrary code execution.\n","is_hidden":false,"release_packages":{"jammy":[{"name":"webkit2gtk","version":"2.44.0-0ubuntu0.22.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.44.0-0ubuntu0.22.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.22.04.1","pocket":"security"}],"mantic":[{"name":"webkit2gtk","version":"2.44.0-0ubuntu0.23.10.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-4.1","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-javascriptcoregtk-6.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-webkit-6.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"gir1.2-webkit2-4.1","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.1-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-1","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libjavascriptcoregtk-6.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-0","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkit2gtk-4.1-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkitgtk-6.0-4","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"libwebkitgtk-6.0-dev","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"},{"name":"webkit2gtk-driver","version":"2.44.0-0ubuntu0.23.10.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.44.0-0ubuntu0.23.10.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2024-23254","CVE-2024-23280","CVE-2024-23284","CVE-2023-42843","CVE-2024-23263","CVE-2023-42950","CVE-2023-42956","CVE-2024-23252"]}]},{"id":"CVE-2024-23226","published":"2024-03-08T00:00:00","updated_at":"2026-09-17T00:43:51.106002+00:00","description":"\nThe issue was addressed with improved memory handling. This issue is fixed\nin iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1,\nwatchOS 10.4. Processing web content may lead to arbitrary code execution.","ubuntu_description":"","notes":[{"author":"jdstrand","note":"webkit receives limited support. For details, see\nhttps://wiki.ubuntu.com/SecurityTeam/FAQ#webkit\nwebkit in Ubuntu uses the JavaScriptCore (JSC) engine, not V8"},{"author":"mdeslaur","note":"It is no longer possible to build new webkit2gtk versions on\nfocal and earlier. Marking as ignored.\nas o 2024-05-26, no indication this affects webkit2gtk"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://support.apple.com/en-us/HT214087","https://support.apple.com/en-us/HT214086","https://support.apple.com/en-us/HT214081","https://support.apple.com/en-us/HT214084","https://support.apple.com/en-us/HT214088","https://github.com/WebKit/WebKit/commit/d8d29d4618457c3fd19c35309136a14d0582e1d3","https://www.cve.org/CVERecord?id=CVE-2024-23226"],"bugs":["https://bugs.webkit.org/show_bug.cgi?id=259694"],"patches":{"webkitgtk":[],"webkit2gtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"wpewebkit":[]},"tags":{},"packages":[{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"}]},{"name":"wpewebkit","source":"https://ubuntu.com/security/cve?package=wpewebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wpewebkit","debian":"https://tracker.debian.org/pkg/wpewebkit","statuses":[{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-1442","published":"2024-03-07T18:15:00","updated_at":"2025-08-04T18:57:07.202196+00:00","description":"\nA user with the permissions to create a data source can use Grafana API to\ncreate a data source with UID set to *.\nDoing this will grant the user access to read, query, edit and delete all\ndata sources within the organization.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://grafana.com/security/security-advisories/cve-2024-1442/","https://www.cve.org/CVERecord?id=CVE-2024-1442"],"bugs":[""],"patches":{"grafana":[]},"tags":{},"packages":[{"name":"grafana","source":"https://ubuntu.com/security/cve?package=grafana","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=grafana","debian":"https://tracker.debian.org/pkg/grafana","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-1351","published":"2024-03-07T17:15:00","updated_at":"2026-02-18T20:01:27.473899+00:00","description":"\nUnder certain configurations of --tlsCAFile and tls.CAFile, MongoDB Server\nmay skip peer certificate validation which may result in untrusted\nconnections to succeed. This may effectively reduce the security guarantees\nprovided by TLS and open connections that should have been closed due to\nfailing certificate validation. This issue affects MongoDB Server v7.0\nversions prior to and including 7.0.5, MongoDB Server v6.0 versions prior\nto and including 6.0.13, MongoDB Server v5.0 versions prior to and\nincluding 5.0.24 and MongoDB Server v4.4 versions prior to and including\n4.4.28.\nRequired Configuration : A server process will allow incoming connections\nto skip peer certificate validation if the server process was started with\nTLS enabled (net.tls.mode set to allowTLS, preferTLS, or requireTLS) and\nwithout a net.tls.CAFile configured.","ubuntu_description":"","notes":[{"author":"john-breton","note":"Patches were released after the switch to SSPL upstream,\nas such we cannot use them to patch Ubuntu releases.\n\nThe hope is a license-compliant third-party will make\npatches available in the future."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://jira.mongodb.org/browse/SERVER-72839","https://www.mongodb.com/docs/v5.0/release-notes/5.0/#5.0.25---february-28--2024","https://www.mongodb.com/docs/v6.0/release-notes/6.0/#6.0.14---feb-28--2024","https://www.mongodb.com/docs/manual/release-notes/7.0/#7.0.6---feb-28--2024","https://www.mongodb.com/docs/manual/release-notes/4.4/#4.4.29---february-28--2024","https://www.cve.org/CVERecord?id=CVE-2024-1351"],"bugs":[""],"patches":{"mongodb":["upstream: https://github.com/mongodb/mongo/commit/c4a8534c26bc3c86b2c4be6128722811055767a0","upstream: https://github.com/mongodb/mongo/commit/1d959ddb773145fc2df52ed6ee0077a6c2f75442","upstream: https://github.com/mongodb/mongo/commit/45d4dc33c2929d8578e45c55d6348d646d02123d","upstream: https://github.com/mongodb/mongo/commit/3073e288eb72a61956ec4034a940689aa861868a","upstream: https://github.com/mongodb/mongo/commit/3e37b1e2a4c341cd456125c804f7700b3056519a"]},"tags":{},"packages":[{"name":"mongodb","source":"https://ubuntu.com/security/cve?package=mongodb","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mongodb","debian":"https://tracker.debian.org/pkg/mongodb","statuses":[{"release_codename":"xenial","status":"deferred","description":"2026-02-18","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2026-02-18","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"deferred","description":"2026-02-18","component":null,"pocket":"security"},{"release_codename":"focal","status":"deferred","description":"2026-02-18","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.4.29, 5.0.25, 6.0.14, 7.0.6, 7.1.0-rc4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-1931","published":"2024-03-07T10:15:00","updated_at":"2025-08-26T00:21:32.135926+00:00","description":"\nNLnet Labs Unbound version 1.18.0 up to and including version 1.19.1\ncontain a vulnerability that can cause denial of service by a certain code\npath that can lead to an infinite loop. Unbound 1.18.0 introduced a feature\nthat removes EDE records from responses with size higher than the client's\nadvertised buffer size. Before removing all the EDE records however, it\nwould try to see if trimming the extra text fields on those records would\nresult in an acceptable size while still retaining the EDE codes. Due to an\nunchecked condition, the code that trims the text of the EDE records could\nloop indefinitely. This happens when Unbound would reply with attached EDE\ninformation on a positive reply and the client's buffer size is smaller\nthan the needed space to include EDE records. The vulnerability can only be\ntriggered when the 'ede: yes' option is used; non default configuration.\nFrom version 1.19.2 on, the code is fixed to avoid looping indefinitely.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"only affects 1.18.0+"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.nlnetlabs.nl/downloads/unbound/CVE-2024-1931.txt","https://www.cve.org/CVERecord?id=CVE-2024-1931"],"bugs":[""],"patches":{"unbound":[]},"tags":{},"packages":[{"name":"unbound","source":"https://ubuntu.com/security/cve?package=unbound","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=unbound","debian":"https://tracker.debian.org/pkg/unbound","statuses":[{"release_codename":"upstream","status":"released","description":"1.19.2-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.19.2-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-1299","published":"2024-03-07T01:15:00","updated_at":"2025-08-26T00:21:13.310346+00:00","description":"\nA privilege escalation vulnerability was discovered in GitLab affecting\nversions 16.8 prior to 16.8.4 and 16.9 prior to 16.9.2. It was possible for\na user with custom role of `manage_group_access_tokens` to rotate group\naccess tokens with owner privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://gitlab.com/gitlab-org/gitlab/-/issues/440745","https://hackerone.com/reports/2356976","https://about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/","https://www.cve.org/CVERecord?id=CVE-2024-1299"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [not maintainable]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-0199","published":"2024-03-07T01:15:00","updated_at":"2025-08-26T00:20:11.718316+00:00","description":"\nAn authorization bypass vulnerability was discovered in GitLab affecting\nversions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to\n16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload\nin an old feature branch to perform malicious actions.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://gitlab.com/gitlab-org/gitlab/-/issues/436977","https://hackerone.com/reports/2295423","https://about.gitlab.com/releases/2024/03/06/security-release-gitlab-16-9-2-released/","https://www.cve.org/CVERecord?id=CVE-2024-0199"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of ESM support, was ignored [not maintainable]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-2314","published":"2024-03-07T00:00:00","updated_at":"2025-08-26T00:22:04.730905+00:00","description":"\nIf kernel headers need to be extracted, bcc will attempt to load them from\na temporary directory. An unprivileged attacker could use this to force bcc\nto load compromised linux headers. Linux distributions which provide kernel\nheaders by default are not affected by default.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":2.8,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2024-2314"],"bugs":[""],"patches":{"bpfcc":["upstream: https://github.com/iovisor/bcc/commit/008ea09e891194c072f2a9305a3c872a241dc342"]},"tags":{},"packages":[{"name":"bpfcc","source":"https://ubuntu.com/security/cve?package=bpfcc","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=bpfcc","debian":"https://tracker.debian.org/pkg/bpfcc","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"kernel headers are provided by system","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"kernel headers are provided by system","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"kernel headers are provided by system","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"kernel headers are provided by system","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"kernel headers are provided by system","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-2236","published":"2024-03-06T22:15:00","updated_at":"2026-09-01T17:37:27.331770+00:00","description":"\nA timing-based side-channel flaw was found in libgcrypt's RSA\nimplementation. This issue may allow a remote attacker to initiate a\nBleichenbacher-style attack, which can lead to the decryption of RSA\nciphertexts.","ubuntu_description":"","notes":[{"author":"","note":"Priority reason:\nlibgcrypt developers consider this to be a low severity issue"},{"author":"mdeslaur","note":"No upstream fix for this issue as of 2026-08-24\nlibgcrypt developers consider this to be a low severity issue\nWhile upstream libgcrypt developers have not created a fix for\nthis issue, Red Hat has created their own fix and it is\navailable in Fedora."}],"codename":null,"priority":"low","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://access.redhat.com/security/cve/CVE-2024-2236","https://lists.gnupg.org/pipermail/gcrypt-devel/2024-March/005607.html","https://github.com/tomato42/marvin-toolkit/tree/master/example/libgcrypt","https://dev.gnupg.org/T7136","https://www.cve.org/CVERecord?id=CVE-2024-2236","https://gitlab.com/redhat-crypto/libgcrypt/libgcrypt-mirror/-/merge_requests/17","https://ubuntu.com/security/notices/USN-8711-1"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=2268268","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1065683","https://dev.gnupg.org/T7136"],"patches":{"libgcrypt11":[],"libgcrypt20":["vendor: https://src.fedoraproject.org/rpms/libgcrypt/blob/9c274d3bde2a67a4defaad5504803fb30ca8c8e4/f/libgcrypt-1.11.0-marvin.patch"]},"tags":{},"packages":[{"name":"libgcrypt11","source":"https://ubuntu.com/security/cve?package=libgcrypt11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgcrypt11","debian":"https://tracker.debian.org/pkg/libgcrypt11","statuses":[{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"libgcrypt20","source":"https://ubuntu.com/security/cve?package=libgcrypt20","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgcrypt20","debian":"https://tracker.debian.org/pkg/libgcrypt20","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1.9.4-3ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.10.3-2ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.12.0-2ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was deferred [2024-09-19]","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was deferred","component":null,"pocket":"security"}]}],"notices_ids":["USN-8711-1"],"notices":[{"id":"USN-8711-1","title":"Libgcrypt vulnerability","summary":"Libgcrypt could be made to expose sensitive information over the network.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-01T16:14:15.119454","description":"It was discovered that Libgcrypt had a timing-based side-channel flaw in\nits RSA implementation. A remote attacker could possibly use this issue to\nobtain sensitive information.","is_hidden":false,"release_packages":{"jammy":[{"name":"libgcrypt20","version":"1.9.4-3ubuntu3.3","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt-mingw-w64-dev","version":"1.9.4-3ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.9.4-3ubuntu3.3","pocket":"security"},{"name":"libgcrypt20","version":"1.9.4-3ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.9.4-3ubuntu3.3","pocket":"security"},{"name":"libgcrypt20-dev","version":"1.9.4-3ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.9.4-3ubuntu3.3","pocket":"security"},{"name":"libgcrypt20-doc","version":"1.9.4-3ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.9.4-3ubuntu3.3","pocket":"security"}],"noble":[{"name":"libgcrypt20","version":"1.10.3-2ubuntu0.2","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt-mingw-w64-dev","version":"1.10.3-2ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.10.3-2ubuntu0.2","pocket":"security"},{"name":"libgcrypt20","version":"1.10.3-2ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.10.3-2ubuntu0.2","pocket":"security"},{"name":"libgcrypt20-dev","version":"1.10.3-2ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.10.3-2ubuntu0.2","pocket":"security"},{"name":"libgcrypt20-doc","version":"1.10.3-2ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.10.3-2ubuntu0.2","pocket":"security"}],"resolute":[{"name":"libgcrypt20","version":"1.12.0-2ubuntu1.1","description":"LGPL Crypto library","is_source":true},{"name":"libgcrypt-bin","version":"1.12.0-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.12.0-2ubuntu1.1","pocket":"security"},{"name":"libgcrypt-mingw-w64-dev","version":"1.12.0-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.12.0-2ubuntu1.1","pocket":"security"},{"name":"libgcrypt20","version":"1.12.0-2ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.12.0-2ubuntu1.1","pocket":"security"},{"name":"libgcrypt20-dev","version":"1.12.0-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.12.0-2ubuntu1.1","pocket":"security"},{"name":"libgcrypt20-doc","version":"1.12.0-2ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libgcrypt20","version_link":"https://launchpad.net/ubuntu/+source/libgcrypt20/1.12.0-2ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2024-2236"]}]},{"id":"CVE-2024-27308","published":"2024-03-06T20:15:00","updated_at":"2025-08-26T00:25:14.885152+00:00","description":"\nMio is a Metal I/O library for Rust. When using named pipes on Windows, mio\nwill under some circumstances return invalid tokens that correspond to\nnamed pipes that have already been deregistered from the mio registry. The\nimpact of this vulnerability depends on how mio is used. For some\napplications, invalid tokens may be ignored or cause a warning or a crash.\nOn the other hand, for applications that store pointers in the tokens, this\nvulnerability may result in a use-after-free. For users of Tokio, this\nvulnerability is serious and can result in a use-after-free in Tokio. The\nvulnerability is Windows-specific, and can only happen if you are using\nnamed pipes. Other IO resources are not affected. This vulnerability has\nbeen fixed in mio v0.8.11. All versions of mio between v0.7.2 and v0.8.10\nare vulnerable. Tokio is vulnerable when you are using a vulnerable version\nof mio AND you are using at least Tokio v1.30.0. Versions of Tokio prior to\nv1.30.0 will ignore invalid tokens, so they are not vulnerable. Vulnerable\nlibraries that use mio can work around this issue by detecting and ignoring\ninvalid tokens.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://rustsec.org/advisories/RUSTSEC-2024-0019.html","https://github.com/tokio-rs/mio/security/advisories/GHSA-r8w9-5wcg-vfj7","https://github.com/tokio-rs/tokio/issues/6369","https://github.com/tokio-rs/mio/pull/1760","https://github.com/tokio-rs/mio/commit/90d4fe00df870acd3d38f3dc4face9aacab8fbb9","https://www.cve.org/CVERecord?id=CVE-2024-27308"],"bugs":[""],"patches":{"rust-mio":[],"rust-mio-0.6":[]},"tags":{},"packages":[{"name":"rust-mio","source":"https://ubuntu.com/security/cve?package=rust-mio","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-mio","debian":"https://tracker.debian.org/pkg/rust-mio","statuses":[{"release_codename":"focal","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"Windows only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Windows-specific","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"Windows only","component":null,"pocket":"security"}]},{"name":"rust-mio-0.6","source":"https://ubuntu.com/security/cve?package=rust-mio-0.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rust-mio-0.6","debian":"https://tracker.debian.org/pkg/rust-mio-0.6","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Vulnerable code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-27304","published":"2024-03-06T19:15:00","updated_at":"2025-07-11T07:57:48.461600+00:00","description":"\npgx is a PostgreSQL driver and toolkit for Go. SQL injection can occur if\nan attacker can cause a single query or bind message to exceed 4 GB in\nsize. An integer overflow in the calculated message size can cause the one\nlarge message to be sent as multiple messages under the attacker's control.\nThe problem is resolved in v4.18.2 and v5.5.4. As a workaround, reject user\ninput large enough to cause a single query or bind message to exceed 4 GB\nin size.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/jackc/pgx/security/advisories/GHSA-mrww-27vc-gghv","https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4 (v5.5.4)","https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8 (v5.5.4)","https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df (v4.18.2)","https://github.com/jackc/pgproto3/security/advisories/GHSA-7jwh-3vrq-q3m8","https://github.com/jackc/pgproto3/commit/945c2126f6db8f3bea7eeebe307c01fe92bca007","https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4","https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8","https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df","https://www.cve.org/CVERecord?id=CVE-2024-27304"],"bugs":[""],"patches":{"golang-github-jackc-pgx":["upstream: https://github.com/jackc/pgx/commit/adbb38f298c76e283ffc7c7a3f571036fea47fd4","upstream: https://github.com/jackc/pgx/commit/c543134753a0c5d22881c12404025724cb05ffd8"],"golang-github-jackc-pgproto3":["upstream: https://github.com/jackc/pgproto3/commit/945c2126f6db8f3bea7eeebe307c01fe92bca007"]},"tags":{},"packages":[{"name":"golang-github-jackc-pgx","source":"https://ubuntu.com/security/cve?package=golang-github-jackc-pgx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-jackc-pgx","debian":"https://tracker.debian.org/pkg/golang-github-jackc-pgx","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"golang-github-jackc-pgproto3","source":"https://ubuntu.com/security/cve?package=golang-github-jackc-pgproto3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-jackc-pgproto3","debian":"https://tracker.debian.org/pkg/golang-github-jackc-pgproto3","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-27289","published":"2024-03-06T19:15:00","updated_at":"2025-07-11T07:57:46.876212+00:00","description":"\npgx is a PostgreSQL driver and toolkit for Go. Prior to version 4.18.2, SQL\ninjection can occur when all of the following conditions are met: the\nnon-default simple protocol is used; a placeholder for a numeric value must\nbe immediately preceded by a minus; there must be a second placeholder for\na string value after the first placeholder; both must be on the same line;\nand both parameter values must be user-controlled. The problem is resolved\nin v4.18.2. As a workaround, do not use the simple protocol or do not place\na minus directly before a placeholder.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/jackc/pgx/security/advisories/GHSA-m7wr-2xf7-cm9p","https://github.com/jackc/pgx/commit/826a89229b8b1cdf18e4190afa437d3df9901b9c (v4.18.2)","https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df","https://www.cve.org/CVERecord?id=CVE-2024-27289"],"bugs":[""],"patches":{"golang-github-jackc-pgx":["upstream: https://github.com/jackc/pgx/commit/826a89229b8b1cdf18e4190afa437d3df9901b9c","upstream: https://github.com/jackc/pgx/commit/f94eb0e2f96782042c96801b5ac448f44f0a81df"]},"tags":{},"packages":[{"name":"golang-github-jackc-pgx","source":"https://ubuntu.com/security/cve?package=golang-github-jackc-pgx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-jackc-pgx","debian":"https://tracker.debian.org/pkg/golang-github-jackc-pgx","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-25111","published":"2024-03-06T19:15:00","updated_at":"2025-08-19T22:11:54.233779+00:00","description":"\nSquid is a web proxy cache. Starting in version 3.5.27 and prior to version\n6.8, Squid may be vulnerable to a Denial of Service attack against HTTP\nChunked decoder due to an uncontrolled recursion bug. This problem allows a\nremote attacker to cause Denial of Service when sending a crafted, chunked,\nencoded HTTP Message. This bug is fixed in Squid version 6.8. In addition,\npatches addressing this problem for the stable releases can be found in\nSquid's patch archives. There is no workaround for this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.squid-cache.org/pipermail/squid-announce/2024-March/000165.html","https://github.com/squid-cache/squid/security/advisories/GHSA-72c2-c3wm-8qxc","https://github.com/squid-cache/squid/pull/1553","https://ubuntu.com/security/notices/USN-6728-1","https://www.cve.org/CVERecord?id=CVE-2024-25111"],"bugs":[""],"patches":{"squid":["upstream: https://github.com/squid-cache/squid/commit/50c5af88bd74208103722f87593a974bb0f0b8e9","upstream: https://github.com/squid-cache/squid/commit/4658d0fc049738c2e6cd25fc0af10e820cf4c11a","upstream: http://www.squid-cache.org/Versions/v6/SQUID-2024_1.patch"],"squid3":[]},"tags":{},"packages":[{"name":"squid","source":"https://ubuntu.com/security/cve?package=squid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid","debian":"https://tracker.debian.org/pkg/squid","statuses":[{"release_codename":"upstream","status":"released","description":"6.8","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"6.1-2ubuntu1.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.10-1ubuntu1.10","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"5.7-0ubuntu0.22.04.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"6.6-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"6.6-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"6.6-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"6.6-1ubuntu4","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"6.6-1ubuntu4","component":null,"pocket":"security"}]},{"name":"squid3","source":"https://ubuntu.com/security/cve?package=squid3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=squid3","debian":"https://tracker.debian.org/pkg/squid3","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6728-1"],"notices":[{"id":"USN-6728-1","title":"Squid vulnerabilities","summary":"Several security issues were fixed in Squid.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-04-10T16:38:15.931201","description":"Joshua Rogers discovered that Squid incorrectly handled collapsed\nforwarding. A remote attacker could possibly use this issue to cause Squid\nto crash, resulting in a denial of service. This issue only affected Ubuntu\n20.04 LTS and Ubuntu 22.04 LTS. (CVE-2023-49288)\n\nJoshua Rogers discovered that Squid incorrectly handled certain structural\nelements. A remote attacker could possibly use this issue to cause Squid to\ncrash, resulting in a denial of service. (CVE-2023-5824)\n\nJoshua Rogers discovered that Squid incorrectly handled Cache Manager error\nresponses. A remote trusted client can possibly use this issue to cause\nSquid to crash, resulting in a denial of service. (CVE-2024-23638)\n\nJoshua Rogers discovered that Squid incorrectly handled the HTTP Chunked\ndecoder. A remote attacker could possibly use this issue to cause Squid to\nstop responding, resulting in a denial of service. (CVE-2024-25111)\n\nJoshua Rogers discovered that Squid incorrectly handled HTTP header\nparsing. A remote trusted client can possibly use this issue to cause\nSquid to crash, resulting in a denial of service. (CVE-2024-25617)\n","is_hidden":false,"release_packages":{"focal":[{"name":"squid","version":"4.10-1ubuntu1.10","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"4.10-1ubuntu1.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.10","pocket":"security"},{"name":"squid-cgi","version":"4.10-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.10","pocket":"security"},{"name":"squid-common","version":"4.10-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.10","pocket":"security"},{"name":"squid-purge","version":"4.10-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.10","pocket":"security"},{"name":"squidclient","version":"4.10-1ubuntu1.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.10","pocket":"security"}],"jammy":[{"name":"squid","version":"5.7-0ubuntu0.22.04.4","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"5.7-0ubuntu0.22.04.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.7-0ubuntu0.22.04.4","pocket":"security"},{"name":"squid-cgi","version":"5.7-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.7-0ubuntu0.22.04.4","pocket":"security"},{"name":"squid-common","version":"5.7-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.7-0ubuntu0.22.04.4","pocket":"security"},{"name":"squid-openssl","version":"5.7-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.7-0ubuntu0.22.04.4","pocket":"security"},{"name":"squid-purge","version":"5.7-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.7-0ubuntu0.22.04.4","pocket":"security"},{"name":"squidclient","version":"5.7-0ubuntu0.22.04.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/5.7-0ubuntu0.22.04.4","pocket":"security"}],"mantic":[{"name":"squid","version":"6.1-2ubuntu1.3","description":"Web proxy cache server","is_source":true},{"name":"squid","version":"6.1-2ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/6.1-2ubuntu1.3","pocket":"security"},{"name":"squid-cgi","version":"6.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/6.1-2ubuntu1.3","pocket":"security"},{"name":"squid-common","version":"6.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/6.1-2ubuntu1.3","pocket":"security"},{"name":"squid-openssl","version":"6.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/6.1-2ubuntu1.3","pocket":"security"},{"name":"squid-purge","version":"6.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/6.1-2ubuntu1.3","pocket":"security"},{"name":"squidclient","version":"6.1-2ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/squid","version_link":"https://launchpad.net/ubuntu/+source/squid/6.1-2ubuntu1.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2024-23638","CVE-2023-5824","CVE-2024-25617","CVE-2024-25111","CVE-2023-49288"]}]},{"id":"CVE-2024-2176","published":"2024-03-06T19:15:00","updated_at":"2025-08-26T00:21:45.853359+00:00","description":"\nUse after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a\nremote attacker to potentially exploit heap corruption via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/325936438","https://www.cve.org/CVERecord?id=CVE-2024-2176"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-2174","published":"2024-03-06T19:15:00","updated_at":"2025-08-26T00:21:45.853359+00:00","description":"\nInappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111\nallowed a remote attacker to potentially exploit heap corruption via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/325866363","https://www.cve.org/CVERecord?id=CVE-2024-2174"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-2173","published":"2024-03-06T19:15:00","updated_at":"2025-08-26T00:21:45.853359+00:00","description":"\nOut of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111\nallowed a remote attacker to perform out of bounds memory access via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser\nin Ubuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop.html","https://issues.chromium.org/issues/325893559","https://www.cve.org/CVERecord?id=CVE-2024-2173"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2024-24761","published":"2024-03-06T18:15:00","updated_at":"2025-08-26T00:22:19.882411+00:00","description":"\nGalette is a membership management web application for non profit\norganizations. Starting in version 1.0.0 and prior to version 1.0.2, public\npages are per default restricted to only administrators and staff members.\nFrom configuration, it is possible to restrict to up-to-date members or to\neveryone. Version 1.0.2 fixes this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/galette/galette/security/advisories/GHSA-jrqg-mpwv-pxpv","https://github.com/galette/galette/commit/a5c18bb9819b8da1b3ef58f3e79577083c657fbb","https://www.cve.org/CVERecord?id=CVE-2024-24761"],"bugs":[""],"patches":{"galette":[]},"tags":{},"packages":[{"name":"galette","source":"https://ubuntu.com/security/cve?package=galette","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=galette","debian":"https://tracker.debian.org/pkg/galette","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2023-50716","published":"2024-03-06T18:15:00","updated_at":"2025-07-11T07:56:38.028905+00:00","description":"\neProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data\nDistribution Service standard of the Object Management Group. Prior to\nversions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7, an invalid DATA_FRAG\nSubmessage causes a bad-free error, and the Fast-DDS process can be\nremotely terminated. If an invalid Data_Frag packet is sent, the\n`Inline_qos, SerializedPayload` member of object `ch` will attempt to\nrelease memory without initialization, resulting in a 'bad-free' error.\nVersions 2.13.0, 2.12.2, 2.11.3, 2.10.2, and 2.6.7 fix this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"ADJACENT","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-5m2f-hvj2-cx2h","https://github.com/eProsima/Fast-DDS/pull/4145","https://www.cve.org/CVERecord?id=CVE-2023-50716"],"bugs":[""],"patches":{"fastdds":["upstream: https://github.com/eProsima/Fast-DDS/pull/4145/commits/54076f0ef3e598ec88a3a4451a41479abe090ce9","upstream: https://github.com/eProsima/Fast-DDS/pull/4145/commits/61a73275a8225433a29d4e285ff9905cb7db7cb4"]},"tags":{},"packages":[{"name":"fastdds","source":"https://ubuntu.com/security/cve?package=fastdds","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=fastdds","debian":"https://tracker.debian.org/pkg/fastdds","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.13.0, 2.12.2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":31480,"limit":20,"total_results":79316}