{"cves":[{"id":"CVE-2022-42319","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:54.605127+00:00","description":"\nXenstore: Guests can cause Xenstore to not free temporary memory When\nworking on a request of a guest, xenstored might need to allocate quite\nlarge amounts of memory temporarily. This memory is freed only after the\nrequest has been finished completely. A request is regarded to be finished\nonly after the guest has read the response message of the request from the\nring page. Thus a guest not reading the response can cause xenstored to not\nfree the temporary memory. This can result in memory shortages causing\nDenial of Service (DoS) of xenstored.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-416.html","https://xenbits.xenproject.org/xsa/advisory-416.txt","http://xenbits.xen.org/xsa/advisory-416.html","http://www.openwall.com/lists/oss-security/2022/11/01/6","https://www.cve.org/CVERecord?id=CVE-2022-42319"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42318","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:54.605127+00:00","description":"\nXenstore: guests can let run xenstored out of memory T[his CNA information\nrecord relates to multiple CVEs; the text explains which\naspects/vulnerabilities correspond to which CVE.] Malicious guests can\ncause xenstored to allocate vast amounts of memory, eventually resulting in\na Denial of Service (DoS) of xenstored. There are multiple ways how guests\ncan cause large memory allocations in xenstored: - - by issuing new\nrequests to xenstored without reading the responses, causing the responses\nto be buffered in memory - - by causing large number of watch events to be\ngenerated via setting up multiple xenstore watches and then e.g. deleting\nmany xenstore nodes below the watched path - - by creating as many nodes as\nallowed with the maximum allowed size and path length in as many\ntransactions as possible - - by accessing many nodes inside a transaction","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-326.html","https://xenbits.xenproject.org/xsa/advisory-326.txt","http://xenbits.xen.org/xsa/advisory-326.html","https://www.cve.org/CVERecord?id=CVE-2022-42318"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42317","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:54.605127+00:00","description":"\nXenstore: guests can let run xenstored out of memory T[his CNA information\nrecord relates to multiple CVEs; the text explains which\naspects/vulnerabilities correspond to which CVE.] Malicious guests can\ncause xenstored to allocate vast amounts of memory, eventually resulting in\na Denial of Service (DoS) of xenstored. There are multiple ways how guests\ncan cause large memory allocations in xenstored: - - by issuing new\nrequests to xenstored without reading the responses, causing the responses\nto be buffered in memory - - by causing large number of watch events to be\ngenerated via setting up multiple xenstore watches and then e.g. deleting\nmany xenstore nodes below the watched path - - by creating as many nodes as\nallowed with the maximum allowed size and path length in as many\ntransactions as possible - - by accessing many nodes inside a transaction","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-326.html","https://xenbits.xenproject.org/xsa/advisory-326.txt","http://xenbits.xen.org/xsa/advisory-326.html","https://www.cve.org/CVERecord?id=CVE-2022-42317"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42316","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:54.605127+00:00","description":"\nXenstore: guests can let run xenstored out of memory T[his CNA information\nrecord relates to multiple CVEs; the text explains which\naspects/vulnerabilities correspond to which CVE.] Malicious guests can\ncause xenstored to allocate vast amounts of memory, eventually resulting in\na Denial of Service (DoS) of xenstored. There are multiple ways how guests\ncan cause large memory allocations in xenstored: - - by issuing new\nrequests to xenstored without reading the responses, causing the responses\nto be buffered in memory - - by causing large number of watch events to be\ngenerated via setting up multiple xenstore watches and then e.g. deleting\nmany xenstore nodes below the watched path - - by creating as many nodes as\nallowed with the maximum allowed size and path length in as many\ntransactions as possible - - by accessing many nodes inside a transaction","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-326.html","https://xenbits.xenproject.org/xsa/advisory-326.txt","http://xenbits.xen.org/xsa/advisory-326.html","https://www.cve.org/CVERecord?id=CVE-2022-42316"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42315","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:54.605127+00:00","description":"\nXenstore: guests can let run xenstored out of memory T[his CNA information\nrecord relates to multiple CVEs; the text explains which\naspects/vulnerabilities correspond to which CVE.] Malicious guests can\ncause xenstored to allocate vast amounts of memory, eventually resulting in\na Denial of Service (DoS) of xenstored. There are multiple ways how guests\ncan cause large memory allocations in xenstored: - - by issuing new\nrequests to xenstored without reading the responses, causing the responses\nto be buffered in memory - - by causing large number of watch events to be\ngenerated via setting up multiple xenstore watches and then e.g. deleting\nmany xenstore nodes below the watched path - - by creating as many nodes as\nallowed with the maximum allowed size and path length in as many\ntransactions as possible - - by accessing many nodes inside a transaction","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-326.html","https://xenbits.xenproject.org/xsa/advisory-326.txt","http://xenbits.xen.org/xsa/advisory-326.html","https://www.cve.org/CVERecord?id=CVE-2022-42315"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42314","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:51.757535+00:00","description":"\nXenstore: guests can let run xenstored out of memory T[his CNA information\nrecord relates to multiple CVEs; the text explains which\naspects/vulnerabilities correspond to which CVE.] Malicious guests can\ncause xenstored to allocate vast amounts of memory, eventually resulting in\na Denial of Service (DoS) of xenstored. There are multiple ways how guests\ncan cause large memory allocations in xenstored: - - by issuing new\nrequests to xenstored without reading the responses, causing the responses\nto be buffered in memory - - by causing large number of watch events to be\ngenerated via setting up multiple xenstore watches and then e.g. deleting\nmany xenstore nodes below the watched path - - by creating as many nodes as\nallowed with the maximum allowed size and path length in as many\ntransactions as possible - - by accessing many nodes inside a transaction","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-326.html","https://xenbits.xenproject.org/xsa/advisory-326.txt","http://xenbits.xen.org/xsa/advisory-326.html","https://www.cve.org/CVERecord?id=CVE-2022-42314"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42313","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:51.757535+00:00","description":"\nXenstore: guests can let run xenstored out of memory T[his CNA information\nrecord relates to multiple CVEs; the text explains which\naspects/vulnerabilities correspond to which CVE.] Malicious guests can\ncause xenstored to allocate vast amounts of memory, eventually resulting in\na Denial of Service (DoS) of xenstored. There are multiple ways how guests\ncan cause large memory allocations in xenstored: - - by issuing new\nrequests to xenstored without reading the responses, causing the responses\nto be buffered in memory - - by causing large number of watch events to be\ngenerated via setting up multiple xenstore watches and then e.g. deleting\nmany xenstore nodes below the watched path - - by creating as many nodes as\nallowed with the maximum allowed size and path length in as many\ntransactions as possible - - by accessing many nodes inside a transaction","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-326.html","https://xenbits.xenproject.org/xsa/advisory-326.txt","http://xenbits.xen.org/xsa/advisory-326.html","https://www.cve.org/CVERecord?id=CVE-2022-42313"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42312","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:51.757535+00:00","description":"\nXenstore: guests can let run xenstored out of memory T[his CNA information\nrecord relates to multiple CVEs; the text explains which\naspects/vulnerabilities correspond to which CVE.] Malicious guests can\ncause xenstored to allocate vast amounts of memory, eventually resulting in\na Denial of Service (DoS) of xenstored. There are multiple ways how guests\ncan cause large memory allocations in xenstored: - - by issuing new\nrequests to xenstored without reading the responses, causing the responses\nto be buffered in memory - - by causing large number of watch events to be\ngenerated via setting up multiple xenstore watches and then e.g. deleting\nmany xenstore nodes below the watched path - - by creating as many nodes as\nallowed with the maximum allowed size and path length in as many\ntransactions as possible - - by accessing many nodes inside a transaction","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-326.html","https://xenbits.xenproject.org/xsa/advisory-326.txt","http://xenbits.xen.org/xsa/advisory-326.html","https://www.cve.org/CVERecord?id=CVE-2022-42312"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42311","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:51.757535+00:00","description":"\nXenstore: guests can let run xenstored out of memory T[his CNA information\nrecord relates to multiple CVEs; the text explains which\naspects/vulnerabilities correspond to which CVE.] Malicious guests can\ncause xenstored to allocate vast amounts of memory, eventually resulting in\na Denial of Service (DoS) of xenstored. There are multiple ways how guests\ncan cause large memory allocations in xenstored: - - by issuing new\nrequests to xenstored without reading the responses, causing the responses\nto be buffered in memory - - by causing large number of watch events to be\ngenerated via setting up multiple xenstore watches and then e.g. deleting\nmany xenstore nodes below the watched path - - by creating as many nodes as\nallowed with the maximum allowed size and path length in as many\ntransactions as possible - - by accessing many nodes inside a transaction","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-326.html","https://xenbits.xenproject.org/xsa/advisory-326.txt","http://xenbits.xen.org/xsa/advisory-326.html","https://www.cve.org/CVERecord?id=CVE-2022-42311"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42310","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:51.757535+00:00","description":"\nXenstore: Guests can create orphaned Xenstore nodes By creating multiple\nnodes inside a transaction resulting in an error, a malicious guest can\ncreate orphaned nodes in the Xenstore data base, as the cleanup after the\nerror will not remove all nodes already created. When the transaction is\ncommitted after this situation, nodes without a valid parent can be made\npermanent in the data base.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-415.html","https://xenbits.xenproject.org/xsa/advisory-415.txt","http://xenbits.xen.org/xsa/advisory-415.html","http://www.openwall.com/lists/oss-security/2022/11/01/5","https://www.cve.org/CVERecord?id=CVE-2022-42310"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42309","published":"2022-11-01T13:15:00","updated_at":"2025-07-11T07:52:51.757535+00:00","description":"\nXenstore: Guests can crash xenstored Due to a bug in the fix of XSA-115 a\nmalicious guest can cause xenstored to use a wrong pointer during node\ncreation in an error path, resulting in a crash of xenstored or a memory\ncorruption in xenstored causing further damage. Entering the error path can\nbe controlled by the guest e.g. by exceeding the quota value of maximum\nnodes per domain.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-414.html","https://xenbits.xenproject.org/xsa/advisory-414.txt","http://xenbits.xen.org/xsa/advisory-414.html","http://www.openwall.com/lists/oss-security/2022/11/01/4","https://www.cve.org/CVERecord?id=CVE-2022-42309"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-42252","published":"2022-11-01T09:15:00","updated_at":"2026-03-19T16:20:30.966189+00:00","description":"\nIf Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26\nor 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via\nsetting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat\ndid not reject a request containing an invalid Content-Length header making\na request smuggling attack possible if Tomcat was located behind a reverse\nproxy that also failed to reject the request with the invalid header.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.apache.org/thread/zzcxzvqfdqn515zfs3dxb7n8gty589sq","https://github.com/apache/tomcat/commit/4c7f4fd09d2cc1692112ef70b8ee23a7a037ae77 (9.0.68)","https://github.com/apache/tomcat/commit/a1c07906d8dcaf7957e5cc97f5cdbac7d18a205a (8.5.83)","https://www.cve.org/CVERecord?id=CVE-2022-42252","https://ubuntu.com/security/notices/USN-6880-1"],"bugs":[""],"patches":{"tomcat6":[],"tomcat7":[],"tomcat8":[],"tomcat9":[],"tomcat10":[]},"tags":{},"packages":[{"name":"tomcat10","source":"https://ubuntu.com/security/cve?package=tomcat10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat10","debian":"https://tracker.debian.org/pkg/tomcat10","statuses":[{"release_codename":"noble","status":"not-affected","description":"10.0.27","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"10.0.27","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"10.0.27","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"tomcat6","source":"https://ubuntu.com/security/cve?package=tomcat6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat6","debian":"https://tracker.debian.org/pkg/tomcat6","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"tomcat7","source":"https://ubuntu.com/security/cve?package=tomcat7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat7","debian":"https://tracker.debian.org/pkg/tomcat7","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"tomcat8","source":"https://ubuntu.com/security/cve?package=tomcat8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat8","debian":"https://tracker.debian.org/pkg/tomcat8","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8.5.82","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"8.0.32","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8.5.39-1ubuntu1~18.04.3+esm1","component":null,"pocket":"esm-apps"}]},{"name":"tomcat9","source":"https://ubuntu.com/security/cve?package=tomcat9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tomcat9","debian":"https://tracker.debian.org/pkg/tomcat9","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"9.0.70","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"9.0.70","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.0.68","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"9.0.16-3ubuntu0.18.04.2+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"9.0.31-1ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"9.0.58-1ubuntu0.1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"oracular","status":"not-affected","description":"9.0.70","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"9.0.70","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"9.0.70","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"9.0.70","component":null,"pocket":"security"}]}],"notices_ids":["USN-6880-1"],"notices":[{"id":"USN-6880-1","title":"Tomcat vulnerability","summary":"Tomcat could allow unintended access to network services.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2024-07-09T01:11:28.149564","description":"Sam Shahsavar discovered that Apache Tomcat did not properly reject \nHTTP requests with an invalid Content-Length header. A remote attacker\ncould possibly use this issue to perform HTTP request smuggling attacks.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"tomcat8","version":"8.5.39-1ubuntu1~18.04.3+esm1","description":"Apache Tomcat 8 - Servlet and JSP engine","is_source":true},{"name":"tomcat9","version":"9.0.16-3ubuntu0.18.04.2+esm1","description":"Apache Tomcat 9 - Servlet and JSP engine","is_source":true},{"name":"libtomcat8-embed-java","version":"8.5.39-1ubuntu1~18.04.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"libtomcat8-java","version":"8.5.39-1ubuntu1~18.04.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"libtomcat9-embed-java","version":"9.0.16-3ubuntu0.18.04.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"libtomcat9-java","version":"9.0.16-3ubuntu0.18.04.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8","version":"8.5.39-1ubuntu1~18.04.3+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-admin","version":"8.5.39-1ubuntu1~18.04.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-common","version":"8.5.39-1ubuntu1~18.04.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-docs","version":"8.5.39-1ubuntu1~18.04.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-examples","version":"8.5.39-1ubuntu1~18.04.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat8-user","version":"8.5.39-1ubuntu1~18.04.3+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat8","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9","version":"9.0.16-3ubuntu0.18.04.2+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-admin","version":"9.0.16-3ubuntu0.18.04.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-common","version":"9.0.16-3ubuntu0.18.04.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-docs","version":"9.0.16-3ubuntu0.18.04.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-examples","version":"9.0.16-3ubuntu0.18.04.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-user","version":"9.0.16-3ubuntu0.18.04.2+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"tomcat9","version":"9.0.31-1ubuntu0.5","description":"Apache Tomcat 9 - Servlet and JSP engine","is_source":true},{"name":"libtomcat9-embed-java","version":"9.0.31-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":"https://launchpad.net/ubuntu/+source/tomcat9/9.0.31-1ubuntu0.5","pocket":"security"},{"name":"libtomcat9-java","version":"9.0.31-1ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":"https://launchpad.net/ubuntu/+source/tomcat9/9.0.31-1ubuntu0.5","pocket":"security"},{"name":"tomcat9","version":"9.0.31-1ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":"https://launchpad.net/ubuntu/+source/tomcat9/9.0.31-1ubuntu0.5","pocket":"security"},{"name":"tomcat9-admin","version":"9.0.31-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":"https://launchpad.net/ubuntu/+source/tomcat9/9.0.31-1ubuntu0.5","pocket":"security"},{"name":"tomcat9-common","version":"9.0.31-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":"https://launchpad.net/ubuntu/+source/tomcat9/9.0.31-1ubuntu0.5","pocket":"security"},{"name":"tomcat9-docs","version":"9.0.31-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":"https://launchpad.net/ubuntu/+source/tomcat9/9.0.31-1ubuntu0.5","pocket":"security"},{"name":"tomcat9-examples","version":"9.0.31-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":"https://launchpad.net/ubuntu/+source/tomcat9/9.0.31-1ubuntu0.5","pocket":"security"},{"name":"tomcat9-user","version":"9.0.31-1ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":"https://launchpad.net/ubuntu/+source/tomcat9/9.0.31-1ubuntu0.5","pocket":"security"}],"jammy":[{"name":"tomcat9","version":"9.0.58-1ubuntu0.1+esm1","description":"Apache Tomcat 9 - Servlet and JSP engine","is_source":true},{"name":"libtomcat9-embed-java","version":"9.0.58-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"libtomcat9-java","version":"9.0.58-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9","version":"9.0.58-1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-admin","version":"9.0.58-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-common","version":"9.0.58-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-docs","version":"9.0.58-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-examples","version":"9.0.58-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"},{"name":"tomcat9-user","version":"9.0.58-1ubuntu0.1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tomcat9","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2022-42252"]}]},{"id":"CVE-2022-3373","published":"2022-11-01T03:15:00","updated_at":"2025-08-25T23:55:20.887144+00:00","description":"\nOut of bounds write in V8 in Google Chrome prior to 106.0.5249.91 allowed a\nremote attacker to perform an out of bounds memory write via a crafted HTML\npage. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3373"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3370","published":"2022-11-01T03:15:00","updated_at":"2025-08-25T23:55:20.887144+00:00","description":"\nUse after free in Custom Elements in Google Chrome prior to 106.0.5249.91\nallowed a remote attacker to potentially exploit heap corruption via a\ncrafted HTML page. (Chromium security severity: High)","ubuntu_description":"","notes":[{"author":"alexmurray","note":"The Debian chromium source package is called chromium-browser in\nUbuntu"},{"author":"mdeslaur","note":"starting with Ubuntu 19.10, the chromium-browser package is just\na script that installs the Chromium snap"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3370"],"bugs":[""],"patches":{"chromium-browser":[]},"tags":{},"packages":[{"name":"chromium-browser","source":"https://ubuntu.com/security/cve?package=chromium-browser","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=chromium-browser","debian":"https://tracker.debian.org/pkg/chromium-browser","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"focal was not-affected [code not present]","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"107.0.5304.87-0ubuntu11.18.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3786","published":"2022-11-01T00:00:00","updated_at":"2025-08-26T12:47:51.952530+00:00","description":"\nA buffer overrun can be triggered in X.509 certificate verification,\nspecifically in name constraint checking. Note that this occurs after\ncertificate chain signature verification and requires either a CA to have\nsigned a malicious certificate or for an application to continue\ncertificate verification despite failure to construct a path to a trusted\nissuer. An attacker can craft a malicious email address in a certificate to\noverflow an arbitrary number of bytes containing the `.' character (decimal\n46) on the stack. This buffer overflow could result in a crash (causing a\ndenial of service). In a TLS client, this can be triggered by connecting to\na malicious server. In a TLS server, this can be triggered if the server\nrequests client authentication and a malicious client connects.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"3.x only\nWhile developing the fix for CVE-2022-3602, a second buffer\noverflow was discovered and this additional CVE was issued.\nThe updated packages that fix this issue ommited the CVE number\nfrom the changelog as it was assigned at a later date."}],"codename":null,"priority":"high","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openssl.org/news/secadv/20221101.txt","https://ubuntu.com/security/notices/USN-5710-1","https://www.cve.org/CVERecord?id=CVE-2022-3786"],"bugs":[""],"patches":{"openssl":[],"openssl1.0":[],"nodejs":[],"edk2":[]},"tags":{},"packages":[{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"bionic","status":"not-affected","description":"uses system openssl1.0","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses openssl 1.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.1.1f-1ubuntu2.16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.7-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.1.1-1ubuntu2.1~18.04.20","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5710-1"],"notices":[{"id":"USN-5710-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2022-11-01T16:24:36.697161","description":"It was discovered that OpenSSL incorrectly handled certain X.509 Email\nAddresses. If a certificate authority were tricked into signing a\nspecially-crafted certificate, a remote attacker could possibly use this\nissue to cause OpenSSL to crash, resulting in a denial of service. The\ndefault compiler options for affected releases reduce the vulnerability to\na denial of service. (CVE-2022-3602, CVE-2022-3786)\n\nIt was discovered that OpenSSL incorrectly handled applications creating\ncustom ciphers via the legacy EVP_CIPHER_meth_new() function. This issue\ncould cause certain applications that mishandled values to the function to\npossibly end up with a NULL cipher and messages in plaintext.\n(CVE-2022-3358)\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"openssl","version":"3.0.5-2ubuntu2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.5-2ubuntu2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2","pocket":"security"},{"name":"openssl","version":"3.0.5-2ubuntu2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2","pocket":"security"},{"name":"libssl-doc","version":"3.0.5-2ubuntu2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2","pocket":"security"},{"name":"libssl3","version":"3.0.5-2ubuntu2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2","pocket":"security"}],"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.7","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-3358","CVE-2022-3602","CVE-2022-3786"]}]},{"id":"CVE-2022-3602","published":"2022-11-01T00:00:00","updated_at":"2025-08-26T12:46:31.228786+00:00","description":"\nA buffer overrun can be triggered in X.509 certificate verification,\nspecifically in name constraint checking. Note that this occurs after\ncertificate chain signature verification and requires either a CA to have\nsigned the malicious certificate or for the application to continue\ncertificate verification despite failure to construct a path to a trusted\nissuer. An attacker can craft a malicious email address to overflow four\nattacker-controlled bytes on the stack. This buffer overflow could result\nin a crash (causing a denial of service) or potentially remote code\nexecution. Many platforms implement stack overflow protections which would\nmitigate against the risk of remote code execution. The risk may be further\nmitigated based on stack layout for any given platform/compiler.\nPre-announcements of CVE-2022-3602 described this issue as CRITICAL.\nFurther analysis based on some of the mitigating factors described above\nhave led this to be downgraded to HIGH. Users are still encouraged to\nupgrade to a new version as soon as possible. In a TLS client, this can be\ntriggered by connecting to a malicious server. In a TLS server, this can be\ntriggered if the server requests client authentication and a malicious\nclient connects. Fixed in OpenSSL 3.0.7 (Affected\n3.0.0,3.0.1,3.0.2,3.0.3,3.0.4,3.0.5,3.0.6).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"3.x only\nUbuntu packages are built with stack protector, reducing the\nimpact of this CVE from remote code execution to a denial of\nservice."}],"codename":null,"priority":"high","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openssl.org/news/secadv/20221101.txt","https://ubuntu.com/security/notices/USN-5710-1","https://www.cve.org/CVERecord?id=CVE-2022-3602"],"bugs":[""],"patches":{"openssl":[],"openssl1.0":[],"nodejs":[],"edk2":[]},"tags":{"openssl":["stack-protector"]},"packages":[{"name":"edk2","source":"https://ubuntu.com/security/cve?package=edk2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=edk2","debian":"https://tracker.debian.org/pkg/edk2","statuses":[{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"nodejs","source":"https://ubuntu.com/security/cve?package=nodejs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nodejs","debian":"https://tracker.debian.org/pkg/nodejs","statuses":[{"release_codename":"bionic","status":"not-affected","description":"uses system openssl1.0","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"uses system openssl1.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"uses openssl 1.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"uses system openssl","component":null,"pocket":"security"}]},{"name":"openssl","source":"https://ubuntu.com/security/cve?package=openssl","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl","debian":"https://tracker.debian.org/pkg/openssl","statuses":[{"release_codename":"jammy","status":"released","description":"3.0.2-0ubuntu1.7","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.7-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.1.1f-1ubuntu2.16","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"3.0.5-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.1.1-1ubuntu2.1~18.04.20","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"openssl1.0","source":"https://ubuntu.com/security/cve?package=openssl1.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openssl1.0","debian":"https://tracker.debian.org/pkg/openssl1.0","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5710-1"],"notices":[{"id":"USN-5710-1","title":"OpenSSL vulnerabilities","summary":"Several security issues were fixed in OpenSSL.\n","instructions":"After a standard system update you need to reboot your computer to make all\nthe necessary changes.\n","references":[],"published":"2022-11-01T16:24:36.697161","description":"It was discovered that OpenSSL incorrectly handled certain X.509 Email\nAddresses. If a certificate authority were tricked into signing a\nspecially-crafted certificate, a remote attacker could possibly use this\nissue to cause OpenSSL to crash, resulting in a denial of service. The\ndefault compiler options for affected releases reduce the vulnerability to\na denial of service. (CVE-2022-3602, CVE-2022-3786)\n\nIt was discovered that OpenSSL incorrectly handled applications creating\ncustom ciphers via the legacy EVP_CIPHER_meth_new() function. This issue\ncould cause certain applications that mishandled values to the function to\npossibly end up with a NULL cipher and messages in plaintext.\n(CVE-2022-3358)\n","is_hidden":false,"release_packages":{"kinetic":[{"name":"openssl","version":"3.0.5-2ubuntu2","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.5-2ubuntu2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2","pocket":"security"},{"name":"openssl","version":"3.0.5-2ubuntu2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2","pocket":"security"},{"name":"libssl-doc","version":"3.0.5-2ubuntu2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2","pocket":"security"},{"name":"libssl3","version":"3.0.5-2ubuntu2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.5-2ubuntu2","pocket":"security"}],"jammy":[{"name":"openssl","version":"3.0.2-0ubuntu1.7","description":"Secure Socket Layer (SSL) cryptographic library and tools","is_source":true},{"name":"libssl-dev","version":"3.0.2-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7","pocket":"security"},{"name":"openssl","version":"3.0.2-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7","pocket":"security"},{"name":"libssl-doc","version":"3.0.2-0ubuntu1.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7","pocket":"security"},{"name":"libssl3","version":"3.0.2-0ubuntu1.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openssl","version_link":"https://launchpad.net/ubuntu/+source/openssl/3.0.2-0ubuntu1.7","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2022-3358","CVE-2022-3602","CVE-2022-3786"]}]},{"id":"CVE-2022-3785","published":"2022-10-31T21:15:00","updated_at":"2025-07-11T07:52:00.478702+00:00","description":"\nA vulnerability, which was classified as critical, has been found in\nAxiomatic Bento4. Affected by this issue is the function\nAP4_DataBuffer::SetDataSize of the component Avcinfo. The manipulation\nleads to heap-based buffer overflow. The attack may be launched remotely.\nThe exploit has been disclosed to the public and may be used. The\nidentifier of this vulnerability is VDB-212564.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"kodi-inputstream-adaptive contains an embedded copy of bento4"}],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3785"],"bugs":[""],"patches":{"kodi-inputstream-adaptive":[]},"tags":{},"packages":[{"name":"kodi-inputstream-adaptive","source":"https://ubuntu.com/security/cve?package=kodi-inputstream-adaptive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kodi-inputstream-adaptive","debian":"https://tracker.debian.org/pkg/kodi-inputstream-adaptive","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-3784","published":"2022-10-31T21:15:00","updated_at":"2025-07-11T07:52:00.478702+00:00","description":"\nA vulnerability classified as critical was found in Axiomatic Bento4\n5e7bb34. Affected by this vulnerability is the function\nAP4_Mp4AudioDsiParser::ReadBits of the file Ap4Mp4AudioInfo.cpp of the\ncomponent mp4hls. The manipulation leads to heap-based buffer overflow. The\nattack can be launched remotely. The exploit has been disclosed to the\npublic and may be used. The associated identifier of this vulnerability is\nVDB-212563.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"kodi-inputstream-adaptive contains an embedded copy of bento4"}],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2022-3784"],"bugs":[""],"patches":{"kodi-inputstream-adaptive":[]},"tags":{},"packages":[{"name":"kodi-inputstream-adaptive","source":"https://ubuntu.com/security/cve?package=kodi-inputstream-adaptive","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kodi-inputstream-adaptive","debian":"https://tracker.debian.org/pkg/kodi-inputstream-adaptive","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-31692","published":"2022-10-31T20:15:00","updated_at":"2025-07-11T07:51:27.611043+00:00","description":"\nSpring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could\nbe susceptible to authorization rules bypass via forward or include\ndispatcher types. Specifically, an application is vulnerable when all of\nthe following are true: The application expects that Spring Security\napplies security to forward and include dispatcher types. The application\nuses the AuthorizationFilter either manually or via the\nauthorizeHttpRequests() method. The application configures the\nFilterChainProxy to apply to forward and/or include requests (e.g.\nspring.security.filter.dispatcher-types = request, error, async, forward,\ninclude). The application may forward or include the request to a higher\nprivilege-secured endpoint.The application configures Spring Security to\napply to every dispatcher type via\nauthorizeHttpRequests().shouldFilterAllDispatcherTypes(true)","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://tanzu.vmware.com/security/cve-2022-31692","https://www.cve.org/CVERecord?id=CVE-2022-31692"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2022-31690","published":"2022-10-31T20:15:00","updated_at":"2025-07-11T07:51:27.611043+00:00","description":"\nSpring Security, versions 5.7 prior to 5.7.5, and 5.6 prior to 5.6.9, and\nolder unsupported versions could be susceptible to a privilege escalation\nunder certain conditions. A malicious user or attacker can modify a request\ninitiated by the Client (via the browser) to the Authorization Server which\ncan lead to a privilege escalation on the subsequent approval. This\nscenario can happen if the Authorization Server responds with an OAuth2\nAccess Token Response containing an empty scope list (per RFC 6749, Section\n5.1) on the subsequent request to the token endpoint to obtain the access\ntoken.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://tanzu.vmware.com/security/cve-2022-31690","https://www.cve.org/CVERecord?id=CVE-2022-31690"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":36680,"limit":20,"total_results":79316}