{"cves":[{"id":"CVE-2020-13941","published":"2020-08-17T13:15:00","updated_at":"2025-07-11T07:43:23.884634+00:00","description":"\nReported in SOLR-14515 (private) and fixed in SOLR-14561 (public), released\nin Solr version 8.6.0. The Replication handler\n(https://lucene.apache.org/solr/guide/8_6/index-replication.html#http-api-commands-for-the-replicationhandler)\nallows commands backup, restore and deleteBackup. Each of these take a\nlocation parameter, which was not validated, i.e you could read/write to\nany location the solr user can access.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.apache.org/thread.html/rf54e7912b7d2b72c63ec54a7afa4adcbf16268dcc63253767dd67d60%40%3Cgeneral.lucene.apache.org%3E","https://www.cve.org/CVERecord?id=CVE-2020-13941"],"bugs":[""],"patches":{"lucene-solr":[]},"tags":{},"packages":[{"name":"lucene-solr","source":"https://ubuntu.com/security/cve?package=lucene-solr","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lucene-solr","debian":"https://tracker.debian.org/pkg/lucene-solr","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14350","published":"2020-08-17T00:00:00","updated_at":"2025-08-18T17:11:22.524601+00:00","description":"\nIt was found that some PostgreSQL extensions did not use search_path safely\nin their installation script. An attacker with sufficient privileges could\nuse this flaw to trick an administrator into executing a specially crafted\nscript, during the installation or update of such extension. This affects\nPostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19,\nand before 9.5.23.","ubuntu_description":"","notes":[{"author":"leosilva","note":"Since we don't have how to give support for postgresql-9.1\nthat is end of life in upstream, marking as ignored to\nprecise.\nsince 9.3 has no long upstream support\nand so far we have no ways to patch it\ndeferred it for -esm-main releases."}],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.postgresql.org/about/news/2060/","https://ubuntu.com/security/notices/USN-4472-1","https://www.cve.org/CVERecord?id=CVE-2020-14350"],"bugs":[""],"patches":{"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[],"postgresql-9.1":[],"postgresql-12":["upstream: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=7eeb1d9861b0a3f453f8b31c7648396cdd7f1e59"]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"10.14-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.14","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"12.4-0ubuntu0.20.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"12.4-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"12.4-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"deferred","description":"2019-08-31","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.5.23","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"9.5.23-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4472-1"],"notices":[{"id":"USN-4472-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.\n","references":[],"published":"2020-08-25T12:20:24.870316","description":"Noah Misch discovered that PostgreSQL incorrectly handled the search_path\nsetting when used with logical replication. A remote attacker could\npossibly use this issue to execute arbitrary SQL code. This issue only\naffected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-14349)\n\nAndres Freund discovered that PostgreSQL incorrectly handled search path\nelements in CREATE EXTENSION. A remote attacker could possibly use this\nissue to execute arbitrary SQL code. (CVE-2020-14350)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"postgresql-10","version":"10.14-0ubuntu0.18.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libecpg-dev","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libecpg6","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libpgtypes3","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libpq-dev","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libpq5","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-client-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-doc-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-plperl-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-plpython-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-plpython3-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-pltcl-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-server-dev-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"}],"focal":[{"name":"postgresql-12","version":"12.4-0ubuntu0.20.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libecpg-dev","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libecpg6","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libpgtypes3","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libpq-dev","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libpq5","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-client-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-doc-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-plperl-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-plpython3-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-pltcl-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-server-dev-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"}],"xenial":[{"name":"postgresql-9.5","version":"9.5.23-0ubuntu0.16.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libecpg-dev","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libecpg6","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libpgtypes3","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libpq-dev","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libpq5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-client-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-contrib-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-doc-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-plperl-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-plpython-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-plpython3-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-pltcl-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-server-dev-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-14349","CVE-2020-14350"]}]},{"id":"CVE-2020-14349","published":"2020-08-17T00:00:00","updated_at":"2025-08-25T23:20:35.740256+00:00","description":"\nIt was found that PostgreSQL versions before 12.4, before 11.9 and before\n10.14 did not properly sanitize the search_path during logical replication.\nAn authenticated attacker could use this flaw in an attack similar to\nCVE-2018-1058, in order to execute arbitrary SQL command in the context of\nthe user used for replication.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.postgresql.org/about/news/2060/","https://ubuntu.com/security/notices/USN-4472-1","https://www.cve.org/CVERecord?id=CVE-2020-14349"],"bugs":[""],"patches":{"postgresql-10":[],"postgresql-9.5":[],"postgresql-9.3":[],"postgresql-9.1":[],"postgresql-12":["upstream: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=11da97024abbe76b8c81e3f2375b2a62e9717c67","upstream: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commit;h=cec57b1a0fbcd3833086ba686897c5883e0a2afc"]},"tags":{},"packages":[{"name":"postgresql-10","source":"https://ubuntu.com/security/cve?package=postgresql-10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-10","debian":"https://tracker.debian.org/pkg/postgresql-10","statuses":[{"release_codename":"bionic","status":"released","description":"10.14-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"10.14","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-12","source":"https://ubuntu.com/security/cve?package=postgresql-12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-12","debian":"https://tracker.debian.org/pkg/postgresql-12","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"12.4-0ubuntu0.20.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"12.4-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.1","source":"https://ubuntu.com/security/cve?package=postgresql-9.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.1","debian":"https://tracker.debian.org/pkg/postgresql-9.1","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.3","source":"https://ubuntu.com/security/cve?package=postgresql-9.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.3","debian":"https://tracker.debian.org/pkg/postgresql-9.3","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"postgresql-9.5","source":"https://ubuntu.com/security/cve?package=postgresql-9.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=postgresql-9.5","debian":"https://tracker.debian.org/pkg/postgresql-9.5","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.5.23","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-4472-1"],"notices":[{"id":"USN-4472-1","title":"PostgreSQL vulnerabilities","summary":"Several security issues were fixed in PostgreSQL.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart PostgreSQL to\nmake all the necessary changes.\n","references":[],"published":"2020-08-25T12:20:24.870316","description":"Noah Misch discovered that PostgreSQL incorrectly handled the search_path\nsetting when used with logical replication. A remote attacker could\npossibly use this issue to execute arbitrary SQL code. This issue only\naffected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-14349)\n\nAndres Freund discovered that PostgreSQL incorrectly handled search path\nelements in CREATE EXTENSION. A remote attacker could possibly use this\nissue to execute arbitrary SQL code. (CVE-2020-14350)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"postgresql-10","version":"10.14-0ubuntu0.18.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libecpg-dev","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libecpg6","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libpgtypes3","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libpq-dev","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"libpq5","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-client-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-doc-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-plperl-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-plpython-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-plpython3-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-pltcl-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"},{"name":"postgresql-server-dev-10","version":"10.14-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-10","version_link":"https://launchpad.net/ubuntu/+source/postgresql-10/10.14-0ubuntu0.18.04.1","pocket":"security"}],"focal":[{"name":"postgresql-12","version":"12.4-0ubuntu0.20.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libecpg-dev","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libecpg6","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libpgtypes3","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libpq-dev","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"libpq5","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-client-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-doc-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-plperl-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-plpython3-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-pltcl-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"},{"name":"postgresql-server-dev-12","version":"12.4-0ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-12","version_link":"https://launchpad.net/ubuntu/+source/postgresql-12/12.4-0ubuntu0.20.04.1","pocket":"security"}],"xenial":[{"name":"postgresql-9.5","version":"9.5.23-0ubuntu0.16.04.1","description":"Object-relational SQL database","is_source":true},{"name":"libecpg-compat3","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libecpg-dev","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libecpg6","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libpgtypes3","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libpq-dev","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"libpq5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-client-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-contrib-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-doc-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-plperl-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-plpython-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-plpython3-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-pltcl-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"},{"name":"postgresql-server-dev-9.5","version":"9.5.23-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5","version_link":"https://launchpad.net/ubuntu/+source/postgresql-9.5/9.5.23-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-14349","CVE-2020-14350"]}]},{"id":"CVE-2020-24361","published":"2020-08-16T04:15:00","updated_at":"2025-08-26T12:22:05.395395+00:00","description":"\nSNMPTT before 1.4.2 allows attackers to execute shell code via EXEC,\nPREXEC, or unknown_trap_exec.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.snmptt.org/changelog.shtml","https://www.cve.org/CVERecord?id=CVE-2020-24361"],"bugs":[""],"patches":{"snmptt":[]},"tags":{},"packages":[{"name":"snmptt","source":"https://ubuntu.com/security/cve?package=snmptt","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=snmptt","debian":"https://tracker.debian.org/pkg/snmptt","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.4.2-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-14353","published":"2020-08-14T20:15:00","updated_at":"2026-07-04T07:49:46.556655+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2017-18270. Reason: This candidate is a duplicate of CVE-2017-18270.\nNotes: All CVE users should reference CVE-2017-18270 instead of this\ncandidate. All references and descriptions in this candidate have been\nremoved to prevent accidental usage","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2020-14353"],"bugs":[""],"patches":{"linux":["break-fix: 69664cf16af4f31cd54d77948a4baf9c7e0ca7b9 237bbd29f7a049d310d907f4b2716a7feef9abf3"],"linux-hwe":[],"linux-hwe-5.4":[],"linux-hwe-edge":[],"linux-lts-trusty":[],"linux-lts-xenial":[],"linux-kvm":[],"linux-aws":[],"linux-aws-5.0":[],"linux-aws-5.3":[],"linux-aws-hwe":[],"linux-azure":[],"linux-azure-4.15":[],"linux-azure-5.3":[],"linux-azure-5.4":[],"linux-azure-edge":[],"linux-gcp":[],"linux-gcp-4.15":[],"linux-gcp-5.3":[],"linux-gcp-edge":[],"linux-gke-4.15":[],"linux-gke-5.0":[],"linux-gke-5.3":[],"linux-oracle":[],"linux-oracle-5.0":[],"linux-oracle-5.3":[],"linux-oem":[],"linux-oem-5.6":[],"linux-oem-osp1":[],"linux-raspi":[],"linux-raspi2":[],"linux-raspi2-5.3":[],"linux-raspi-5.4":[],"linux-riscv":[],"linux-snapdragon":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.13.0-17.20","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-9.12","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-98.121","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.13.0-157.207","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1039.48","component":null,"pocket":"security"}]},{"name":"linux-aws-5.0","source":"https://ubuntu.com/security/cve?package=linux-aws-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.0","debian":"https://tracker.debian.org/pkg/linux-aws-5.0","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-aws-5.3","source":"https://ubuntu.com/security/cve?package=linux-aws-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.3","debian":"https://tracker.debian.org/pkg/linux-aws-5.3","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.3.0-1016.17~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1030.31~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"focal","status":"not-affected","description":"5.4.0-1006.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-1005.7","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1082.92","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.3","source":"https://ubuntu.com/security/cve?package=linux-azure-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.3","debian":"https://tracker.debian.org/pkg/linux-azure-5.3","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.3.0-1007.8~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1020.20~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-1002.5","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1071.81","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.3","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.3","debian":"https://tracker.debian.org/pkg/linux-gcp-5.3","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-gcp-edge","source":"https://ubuntu.com/security/cve?package=linux-gcp-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-edge","debian":"https://tracker.debian.org/pkg/linux-gcp-edge","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-gke-4.15","source":"https://ubuntu.com/security/cve?package=linux-gke-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke-4.15","debian":"https://tracker.debian.org/pkg/linux-gke-4.15","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1030.32","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke-5.0","source":"https://ubuntu.com/security/cve?package=linux-gke-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke-5.0","debian":"https://tracker.debian.org/pkg/linux-gke-5.0","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke-5.3","source":"https://ubuntu.com/security/cve?package=linux-gke-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke-5.3","debian":"https://tracker.debian.org/pkg/linux-gke-5.3","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.18.0-13.14~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-26.29~16.04.2","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.4.0-37.41~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1009.14","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-98.121~14.04.1","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-5.6","source":"https://ubuntu.com/security/cve?package=linux-oem-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-5.6","debian":"https://tracker.debian.org/pkg/linux-oem-5.6","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.6.0-1007.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-osp1","source":"https://ubuntu.com/security/cve?package=linux-oem-osp1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-osp1","debian":"https://tracker.debian.org/pkg/linux-oem-osp1","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1007.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1007.9~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.0","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.0","debian":"https://tracker.debian.org/pkg/linux-oracle-5.0","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.3","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.3","debian":"https://tracker.debian.org/pkg/linux-oracle-5.3","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1013.13~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.13.0-1006.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1076.84","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2-5.3","source":"https://ubuntu.com/security/cve?package=linux-raspi2-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2-5.3","debian":"https://tracker.debian.org/pkg/linux-raspi2-5.3","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.3.0-1017.19~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-24.28","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.4.0-1078.83","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.14~rc3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1078.83","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-0255","published":"2020-08-14T20:15:00","updated_at":"2026-07-04T07:50:15.966240+00:00","description":"\nRejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs:\nCVE-2020-10751. Reason: This candidate is a duplicate of CVE-2020-10751.\nNotes: All CVE users should reference CVE-2020-10751 instead of this\ncandidate. All references and descriptions in this candidate have been\nremoved to prevent accidental usage","ubuntu_description":"","notes":[{"author":"cascardo","note":"This is a duplicate of CVE-2020-10751."}],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://git.kernel.org/linus/fb73974172ffaaf57a7c42f35424d9aece1a5af6","https://android.googlesource.com/kernel/common/+/fb73974172ff","https://source.android.com/security/bulletin/2020-08-01","https://www.cve.org/CVERecord?id=CVE-2020-0255"],"bugs":[""],"patches":{"linux":["break-fix: - fb73974172ffaaf57a7c42f35424d9aece1a5af6"],"linux-hwe":[],"linux-hwe-5.4":[],"linux-hwe-edge":[],"linux-lts-trusty":[],"linux-lts-xenial":[],"linux-kvm":[],"linux-aws":[],"linux-aws-5.0":[],"linux-aws-5.3":[],"linux-aws-hwe":[],"linux-azure":[],"linux-azure-4.15":[],"linux-azure-5.3":[],"linux-azure-5.4":[],"linux-azure-edge":[],"linux-gcp":[],"linux-gcp-4.15":[],"linux-gcp-5.3":[],"linux-gcp-edge":[],"linux-gke-4.15":[],"linux-gke-5.0":[],"linux-gke-5.3":[],"linux-oracle":[],"linux-oracle-5.0":[],"linux-oracle-5.3":[],"linux-oem":[],"linux-oem-5.6":[],"linux-oem-osp1":[],"linux-raspi":[],"linux-raspi2":[],"linux-raspi2-5.3":[],"linux-raspi-5.4":[],"linux-riscv":[],"linux-snapdragon":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-106.107","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"5.4.0-37.41","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-184.214","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1073.77","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"5.4.0-1015.15","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1109.120","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-aws-5.0","source":"https://ubuntu.com/security/cve?package=linux-aws-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.0","debian":"https://tracker.debian.org/pkg/linux-aws-5.0","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-aws-5.3","source":"https://ubuntu.com/security/cve?package=linux-aws-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.3","debian":"https://tracker.debian.org/pkg/linux-aws-5.3","statuses":[{"release_codename":"bionic","status":"released","description":"5.3.0-1030.32~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1073.77~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"focal","status":"released","description":"5.4.0-1016.16","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1089.99~16.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1089.99","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.3","source":"https://ubuntu.com/security/cve?package=linux-azure-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.3","debian":"https://tracker.debian.org/pkg/linux-azure-5.3","statuses":[{"release_codename":"bionic","status":"released","description":"5.3.0-1032.33~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1020.20~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"focal","status":"released","description":"5.4.0-1015.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1077.87~16.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1077.87","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.3","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.3","debian":"https://tracker.debian.org/pkg/linux-gcp-5.3","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-gcp-edge","source":"https://ubuntu.com/security/cve?package=linux-gcp-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-edge","debian":"https://tracker.debian.org/pkg/linux-gcp-edge","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-gke-4.15","source":"https://ubuntu.com/security/cve?package=linux-gke-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke-4.15","debian":"https://tracker.debian.org/pkg/linux-gke-4.15","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1063.66","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke-5.0","source":"https://ubuntu.com/security/cve?package=linux-gke-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke-5.0","debian":"https://tracker.debian.org/pkg/linux-gke-5.0","statuses":[{"release_codename":"bionic","status":"released","description":"5.0.0-1043.44","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke-5.3","source":"https://ubuntu.com/security/cve?package=linux-gke-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke-5.3","debian":"https://tracker.debian.org/pkg/linux-gke-5.3","statuses":[{"release_codename":"bionic","status":"released","description":"5.3.0-1030.32~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"released","description":"5.3.0-62.56~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-106.107~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.4.0-37.41~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1067.68","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"5.4.0-1015.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1075.82","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1087.97","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-5.6","source":"https://ubuntu.com/security/cve?package=linux-oem-5.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-5.6","debian":"https://tracker.debian.org/pkg/linux-oem-5.6","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.6.0-1011.11","component":null,"pocket":"security"}]},{"name":"linux-oem-osp1","source":"https://ubuntu.com/security/cve?package=linux-oem-osp1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-osp1","debian":"https://tracker.debian.org/pkg/linux-oem-osp1","statuses":[{"release_codename":"bionic","status":"released","description":"5.0.0-1063.68","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1045.49","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"5.4.0-1015.15","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1045.49~16.04.1","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.0","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.0","debian":"https://tracker.debian.org/pkg/linux-oracle-5.0","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.3","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.3","debian":"https://tracker.debian.org/pkg/linux-oracle-5.3","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"5.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1013.13~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1063.67","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1134.143","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2-5.3","source":"https://ubuntu.com/security/cve?package=linux-raspi2-5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2-5.3","debian":"https://tracker.debian.org/pkg/linux-raspi2-5.3","statuses":[{"release_codename":"bionic","status":"released","description":"5.3.0-1028.30~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"5.4.0-27.31","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1080.87","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.7~rc4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1138.146","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-15694","published":"2020-08-14T19:15:00","updated_at":"2025-08-26T12:20:45.675954+00:00","description":"\nIn Nim 1.2.4, the standard library httpClient fails to properly validate\nthe server response. For example, httpClient.get().contentLength() does not\nraise any error if a malicious server provides a negative Content-Length.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/httpclient.nim#L241","https://nim-lang.org/blog/2020/07/30/versions-126-and-108-released.html","https://www.cve.org/CVERecord?id=CVE-2020-15694"],"bugs":[""],"patches":{"nim":[]},"tags":{},"packages":[{"name":"nim","source":"https://ubuntu.com/security/cve?package=nim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nim","debian":"https://tracker.debian.org/pkg/nim","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-15693","published":"2020-08-14T19:15:00","updated_at":"2025-08-26T12:20:30.893186+00:00","description":"\nIn Nim 1.2.4, the standard library httpClient is vulnerable to a CR-LF\ninjection in the target URL. An injection is possible if the attacker\ncontrols any part of the URL provided in a call (such as httpClient.get or\nhttpClient.post), the User-Agent header value, or custom HTTP header names\nor values.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/httpclient.nim#L1023","https://nim-lang.org/blog/2020/07/30/versions-126-and-108-released.html","https://www.cve.org/CVERecord?id=CVE-2020-15693"],"bugs":[""],"patches":{"nim":[]},"tags":{},"packages":[{"name":"nim","source":"https://ubuntu.com/security/cve?package=nim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nim","debian":"https://tracker.debian.org/pkg/nim","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.2.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-15692","published":"2020-08-14T19:15:00","updated_at":"2025-08-26T12:20:30.893186+00:00","description":"\nIn Nim 1.2.4, the standard library browsers mishandles the URL argument to\nbrowsers.openDefaultBrowser. This argument can be a local file path that\nwill be opened in the default explorer. An attacker can pass one argument\nto the underlying open command to execute arbitrary registered system\ncommands.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/nim-lang/Nim/blob/dc5a40f3f39c6ea672e6dc6aca7f8118a69dda99/lib/pure/browsers.nim#L48","https://nim-lang.org/blog/2020/07/30/versions-126-and-108-released.html","https://www.cve.org/CVERecord?id=CVE-2020-15692"],"bugs":[""],"patches":{"nim":["upstream: https://github.com/nim-lang/Nim/commit/d0a28576751b1b7e8c935ebcb75d44c3d189877e"]},"tags":{},"packages":[{"name":"nim","source":"https://ubuntu.com/security/cve?package=nim","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=nim","debian":"https://tracker.debian.org/pkg/nim","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1.2.6-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1.2.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-12648","published":"2020-08-14T14:15:00","updated_at":"2025-08-26T12:18:59.224745+00:00","description":"\nA cross-site scripting (XSS) vulnerability in TinyMCE 5.2.1 and earlier\nallows remote attackers to inject arbitrary web script when configured in\nclassic editing mode.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://labs.bishopfox.com/advisories/tinymce-version-5.2.1","https://www.cve.org/CVERecord?id=CVE-2020-12648"],"bugs":[""],"patches":{"tinymce":[]},"tags":{},"packages":[{"name":"tinymce","source":"https://ubuntu.com/security/cve?package=tinymce","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tinymce","debian":"https://tracker.debian.org/pkg/tinymce","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-17380","published":"2020-08-14T00:00:00","updated_at":"2026-06-09T18:40:16.717891+00:00","description":"\nA heap-based buffer overflow was found in QEMU through 5.0.0 in the SDHCI\ndevice emulation support. It could occur while doing a multi block SDMA\ntransfer via the sdhci_sdma_transfer_multi_blocks() routine in\nhw/sd/sdhci.c. A guest user or process could use this flaw to crash the\nQEMU process on the host, resulting in a denial of service condition, or\npotentially execute arbitrary code with privileges of the QEMU process on\nthe host.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"see if there are other relevant commits"}],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4650-1","https://www.cve.org/CVERecord?id=CVE-2020-17380","https://ubuntu.com/security/notices/USN-8412-1"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1862167","https://bugs.launchpad.net/qemu/+bug/1892960"],"patches":{"qemu-kvm":[],"qemu":["other: https://lists.nongnu.org/archive/html/qemu-devel/2020-09/msg01175.html","upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=dfba99f17feb6d4a129da19d38df1bcd8579d1c3"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"impish","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:5.2+dfsg-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:2.11+dfsg-1ubuntu7.34","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:4.2-3ubuntu6.10","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1:5.0-5ubuntu9.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.48","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:5.2+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.47+esm6","component":null,"pocket":"esm-infra-legacy"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4650-1","USN-8412-1"],"notices":[{"id":"USN-4650-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2020-11-30T12:25:14.002634","description":"Alexander Bulekov discovered that QEMU incorrectly handled SDHCI device\nemulation. An attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode on the host. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile. \n(CVE-2020-17380)\n\nSergej Schumilo, Cornelius Aschermann, and Simon Wrner discovered that QEMU\nincorrectly handled USB device emulation. An attacker inside the guest\ncould use this issue to cause QEMU to crash, resulting in a denial of\nservice. (CVE-2020-25084)\n\nSergej Schumilo, Cornelius Aschermann, and Simon Wrner discovered that QEMU\nincorrectly handled SDHCI device emulation. An attacker inside the guest\ncould use this issue to cause QEMU to crash, resulting in a denial of\nservice. (CVE-2020-25085)\n\nGaoning Pan, Yongkang Jia, and Yi Ren discovered that QEMU incorrectly\nhandled USB device emulation. An attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2020-25624)\n\nIt was discovered that QEMU incorrectly handled USB device emulation. An\nattacker inside the guest could use this issue to cause QEMU to hang,\nresulting in a denial of service. (CVE-2020-25625)\n\nCheolwoo Myung discovered that QEMU incorrectly handled USB device\nemulation. An attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2020-25723)\n\nGaoning Pan discovered that QEMU incorrectly handled ATI graphics device\nemulation. An attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. This issue only affected Ubuntu\n20.04 LTS and Ubuntu 20.10. (CVE-2020-27616)\n\nGaoning Pan discovered that QEMU incorrectly handled networking. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2020-27617)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.34","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-kvm","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-system","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-system-common","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-user","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-user-static","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"},{"name":"qemu-utils","version":"1:2.11+dfsg-1ubuntu7.34","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.34","pocket":"security"}],"focal":[{"name":"qemu","version":"1:4.2-3ubuntu6.10","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-block-extra","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-guest-agent","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-kvm","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-arm","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-common","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-data","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-gui","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-mips","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-misc","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-ppc","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-s390x","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-sparc","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-x86","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-x86-microvm","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-system-x86-xen","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-user","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-user-static","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"},{"name":"qemu-utils","version":"1:4.2-3ubuntu6.10","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.10","pocket":"security"}],"groovy":[{"name":"qemu","version":"1:5.0-5ubuntu9.2","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-block-extra","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-guest-agent","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-kvm","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-arm","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-common","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-data","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-gui","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-mips","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-misc","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-ppc","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-s390x","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-sparc","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-x86","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-x86-microvm","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-system-x86-xen","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-user","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-user-static","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"},{"name":"qemu-utils","version":"1:5.0-5ubuntu9.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.2","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.48","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.48","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.48","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-25624","CVE-2020-27616","CVE-2020-25723","CVE-2020-25625","CVE-2020-17380","CVE-2020-27617","CVE-2020-25085","CVE-2020-25084"]},{"id":"USN-8412-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.","references":[],"published":"2026-06-09T16:22:49.156514","description":"Felipe Franciosi, Raphael Norwitz, and Peter Turschmid discovered that the\niSCSI block driver in QEMU incorrectly handled certain responses from an\niSCSI server. A remote attacker could possibly use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-1711)\n\nIt was discovered that the iSCSI block driver in QEMU incorrectly handled\ncertain memory operations, leading to a heap-based buffer over-read. An\nattacker could possibly use this issue to expose sensitive information from\nthe host. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-11947)\n\nZiming Zhang discovered that the SM501 display driver in QEMU contained an\ninteger overflow. A local attacker could possibly use this issue to cause\nQEMU to crash, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS. (CVE-2020-12829)\n\nGaoning Pan and Xingwei Li discovered that the USB xHCI controller\nimplementation in QEMU contained an infinite loop. An attacker inside the\nguest could possibly use this issue to cause QEMU to hang, resulting in a\ndenial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04\nLTS, and Ubuntu 18.04 LTS. (CVE-2020-14394)\n\nLei Sun discovered that QEMU incorrectly handled certain MemoryRegionOps\nobjects, leading to a NULL pointer dereference. An attacker inside the\nguest could possibly use this issue to cause QEMU to crash, resulting in a\ndenial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2020-15469)\n\nAlexander Bulekov discovered that the e1000e network device implementation\nin QEMU contained a use-after-free. An attacker inside the guest could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-15859)\n\nZiming Zhang discovered that the XGMAC Ethernet controller in QEMU\ncontained a buffer overflow. An attacker inside the guest could possibly\nuse this issue to cause QEMU to crash, resulting in a denial of service, or\npossibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2020-15863)\n\nAlexander Bulekov discovered that the SDHCI device emulation in QEMU\ncontained a heap-based buffer overflow. An attacker inside the guest could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. This issue only affected\nUbuntu 14.04 LTS. (CVE-2020-17380)\n\nSergej Schumilo, Cornelius Aschermann, and Simon Wörner discovered that the\nUSB xHCI controller implementation in QEMU did not check a return value,\nleading to a use-after-free. An attacker inside the guest could possibly\nuse this issue to cause QEMU to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2020-25084)\n\nGaoning Pan, Yongkang Jia, and Yi Ren discovered that the USB OHCI\ncontroller implementation in QEMU contained a stack-based buffer over-read.\nAn attacker inside the guest could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS. (CVE-2020-25624)\n\nIt was discovered that the USB OHCI controller implementation in QEMU\ncontained an infinite loop. An attacker inside the guest could possibly use\nthis issue to cause QEMU to consume resources, resulting in a denial of\nservice. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-25625)\n\nCheolwoo Myung discovered that the USB EHCI emulation in QEMU did not\nhandle DMA memory map failures, leading to a reachable assertion. An\nattacker inside the guest could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS. (CVE-2020-25723)\n\nGaoning Pan discovered that the network device emulation in QEMU could be\nmade to trigger an assertion failure when processing packets that lacked a\nvalid layer 3 protocol. An attacker inside the guest could possibly use\nthis issue to cause QEMU to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2020-27617)\n\nWenxiang Qian discovered that the ATAPI emulation in QEMU did not properly\nvalidate a buffer index, leading to an out-of-bounds read. An attacker\ninside the guest could possibly use this issue to expose sensitive\ninformation or cause QEMU to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2020-29443)\n\nCheolwoo Myung discovered that the ESP SCSI emulation in QEMU contained a\nNULL pointer dereference. An attacker inside the guest could possibly use\nthis issue to cause QEMU to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2020-35504)\n\nCheolwoo Myung discovered that the am53c974 SCSI host bus adapter emulation\nin QEMU contained a NULL pointer dereference. An attacker inside the guest\ncould possibly use this issue to cause QEMU to crash, resulting in a denial\nof service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2020-35505)\n\nIt was discovered that the SDHCI controller emulation in QEMU contained\nout-of-bounds read and write issues. An attacker inside the guest could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3409)\n\nIt was discovered that several network device emulations in QEMU contained\nan infinite loop when operating in loopback mode. An attacker inside the\nguest could possibly use this issue to cause QEMU to crash, resulting in a\ndenial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2021-3416)\n\nAlexander Bulekov discovered that the floppy disk emulation in QEMU\ncontained a heap-based buffer overflow. An attacker inside the guest could\npossibly use this issue to expose sensitive information or cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3507)\n\nRemy Noel discovered that the USB redirector device emulation in QEMU\nperformed an unbounded stack allocation when combining USB packets. An\nattacker inside the guest could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3527)\n\nIt was discovered that the QXL display device emulation in QEMU contained\nan integer overflow, leading to a heap-based buffer overflow. An attacker\ninside the guest could possibly use this issue to cause QEMU to crash,\nresulting in a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-4206)\n\nIt was discovered that the QXL display device emulation in QEMU performed a\ndouble fetch of guest-controlled values, leading to a heap-based buffer\noverflow. An attacker inside the guest could possibly use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04\nLTS. (CVE-2021-4207)\n\nIt was discovered that the 9pfs server implementation in QEMU contained a\nrace condition, leading to a use-after-free. A malicious 9p client could\npossibly use this issue to escalate privileges. This issue only affected\nUbuntu 14.04 LTS. (CVE-2021-20181)\n\nGaoning Pan discovered that the floppy disk emulation in QEMU contained a\nNULL pointer dereference. An attacker inside the guest could possibly use\nthis issue to cause QEMU to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-20196)\n\nGaoning Pan discovered that the vmxnet3 network device emulation in QEMU\ncontained an integer overflow. An attacker inside the guest could possibly\nuse this issue to cause QEMU to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2021-20203)\n\nIt was discovered that the ARM Generic Interrupt Controller emulation in\nQEMU contained an out-of-bounds heap access. An attacker inside the guest\ncould possibly use this issue to cause QEMU to crash, resulting in a denial\nof service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2021-20221)\n\nAlexander Bulekov, Cheolwoo Myung, Sergej Schumilo, Cornelius Aschermann,\nand Simon Wörner discovered that the e1000 network device emulation in QEMU\ncontained an infinite loop. An attacker inside the guest could possibly use\nthis issue to cause QEMU to consume resources, resulting in a denial of\nservice. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2021-20257)\n\nIt was discovered that the 9p passthrough file system implementation in\nQEMU did not prevent opening special files on the host. A malicious guest\ncould possibly use this issue to escape the exported 9p tree. This issue\nonly affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.\n(CVE-2023-2861)\n\nIt was discovered that the virtio crypto device emulation in QEMU did not\nproperly validate certain buffer lengths, leading to a heap buffer\noverflow. An attacker inside the guest could possibly use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-3180)\n\nIt was discovered that the built-in VNC server in QEMU contained a NULL\npointer dereference when cleaning up a connection that failed during the\nhandshake. A remote attacker could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n18.04 LTS. (CVE-2023-3354)\n\nIt was discovered that QEMU could incorrectly direct a guest I/O operation\nto disk offset 0 instead of the intended offset. An attacker inside the\nguest could possibly use this issue to read or overwrite sensitive data,\npotentially gaining control of the host. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2023-5088)\n\nIt was discovered that several virtio device emulations in QEMU did not\nproperly guard against DMA reentrancy, leading to a double free. An\nattacker inside the guest could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2024-3446)\n\nIt was discovered that the SDHCI device emulation in QEMU contained a heap-\nbased buffer overflow. An attacker inside the guest could possibly use this\nissue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2024-3447)\n\nIt was discovered that the QEMU disk image utility (qemu-img) did not\nproperly handle certain crafted image files. An attacker could possibly use\nthis issue to cause qemu-img to consume excessive resources or access an\nunintended external file, resulting in a denial of service. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2024-4467)\n\nCyrille Chatras discovered that the LSI53C895A SCSI Host Bus Adapter\nemulation in QEMU contained a use-after-free. An attacker inside the guest\ncould possibly use this issue to cause QEMU to crash, resulting in a denial\nof service, or possibly execute arbitrary code. (CVE-2024-6519)\n\nIt was discovered that the NBD server in QEMU contained an improper\nsynchronization issue during socket closure. A remote attacker could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice. (CVE-2024-7409)\n\nIt was discovered that the USB emulation in QEMU contained a reachable\nassertion. An attacker inside the guest could possibly use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2024-8354)\n\nIt was discovered that QEMU incorrectly handled resources during the VNC\nWebSocket handshake, leading to a use-after-free. A remote attacker could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2025-11234)\n\nIt was discovered that QEMU could be made to read out of bounds when\nreading VMDK images. An attacker could possibly use this issue to expose\nsensitive information or cause QEMU to crash, resulting in a denial of\nservice. (CVE-2026-2243)","is_hidden":false,"release_packages":{"bionic":[{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.42+esm5","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-block-extra","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-guest-agent","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-kvm","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-arm","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-common","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-mips","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-misc","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-ppc","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-s390x","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-sparc","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-x86","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user-binfmt","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user-static","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-utils","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"qemu","version":"1:4.2-3ubuntu6.30+esm1","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-block-extra","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-guest-agent","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-kvm","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-arm","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-common","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-data","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-gui","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-mips","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-misc","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-ppc","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-s390x","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-sparc","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-x86","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-x86-microvm","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-x86-xen","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user-binfmt","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user-static","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-utils","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.47+esm6","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.51+esm4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2021-3416","CVE-2020-15469","CVE-2020-1711","CVE-2021-3409","CVE-2024-3447","CVE-2023-5088","CVE-2020-29443","CVE-2020-35504","CVE-2020-35505","CVE-2020-25723","CVE-2021-4206","CVE-2024-3446","CVE-2024-7409","CVE-2024-8354","CVE-2020-11947","CVE-2026-2243","CVE-2023-3180","CVE-2021-4207","CVE-2021-20221","CVE-2020-27617","CVE-2023-3354","CVE-2020-14394","CVE-2020-15863","CVE-2020-25084","CVE-2024-6519","CVE-2024-4467","CVE-2021-3527","CVE-2020-25625","CVE-2021-20257","CVE-2020-25624","CVE-2021-3507","CVE-2025-11234","CVE-2021-20203","CVE-2020-17380","CVE-2023-2861","CVE-2021-20196","CVE-2021-20181","CVE-2020-12829","CVE-2020-15859"]}]},{"id":"CVE-2020-24345","published":"2020-08-13T19:15:00","updated_at":"2025-08-04T19:35:15.441704+00:00","description":"\nJerryScript through 2.3.0 allows stack consumption via function a(){new new\nProxy(a,{})}JSON.parse(\"[]\",a). NOTE: the vendor states that the problem is\nthe lack of the --stack-limit option","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2020-24345"],"bugs":[""],"patches":{"iotjs":[]},"tags":{},"packages":[{"name":"iotjs","source":"https://ubuntu.com/security/cve?package=iotjs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iotjs","debian":"https://tracker.debian.org/pkg/iotjs","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-24344","published":"2020-08-13T19:15:00","updated_at":"2025-08-26T12:22:05.395395+00:00","description":"\nJerryScript through 2.3.0 has a (function({a=arguments}){const arguments})\nbuffer over-read.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/jerryscript-project/jerryscript/issues/3976","https://github.com/jerryscript-project/jerryscript/commit/841d536fce1ce29267cdf0ea12be4026e1c35d3a","https://www.cve.org/CVERecord?id=CVE-2020-24344"],"bugs":[""],"patches":{"iotjs":[]},"tags":{},"packages":[{"name":"iotjs","source":"https://ubuntu.com/security/cve?package=iotjs","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=iotjs","debian":"https://tracker.debian.org/pkg/iotjs","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-24342","published":"2020-08-13T19:15:00","updated_at":"2025-08-25T23:23:51.978833+00:00","description":"\nLua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because\na protection mechanism wrongly calls luaD_callnoyield twice in a row.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"couldn't reproduce on lua earlier than 5.4, and problematic code\ndoesn't seem present. Marking as not-affected."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://lua-users.org/lists/lua-l/2020-07/msg00052.html","https://www.cve.org/CVERecord?id=CVE-2020-24342"],"bugs":[""],"patches":{"lua50":[],"lua5.1":[],"lua5.2":[],"lua5.3":[],"lua5.4":["upstream: https://github.com/lua/lua/commit/34affe7a63fc5d842580a9f23616d057e17dfe27"]},"tags":{},"packages":[{"name":"lua5.1","source":"https://ubuntu.com/security/cve?package=lua5.1","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lua5.1","debian":"https://tracker.debian.org/pkg/lua5.1","statuses":[{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"lua5.2","source":"https://ubuntu.com/security/cve?package=lua5.2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lua5.2","debian":"https://tracker.debian.org/pkg/lua5.2","statuses":[{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"lua5.3","source":"https://ubuntu.com/security/cve?package=lua5.3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lua5.3","debian":"https://tracker.debian.org/pkg/lua5.3","statuses":[{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]},{"name":"lua5.4","source":"https://ubuntu.com/security/cve?package=lua5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lua5.4","debian":"https://tracker.debian.org/pkg/lua5.4","statuses":[{"release_codename":"impish","status":"not-affected","description":"5.4.1-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"5.4.1-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.4.1-1","component":null,"pocket":"security"}]},{"name":"lua50","source":"https://ubuntu.com/security/cve?package=lua50","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=lua50","debian":"https://tracker.debian.org/pkg/lua50","statuses":[{"release_codename":"impish","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-24332","published":"2020-08-13T17:15:00","updated_at":"2025-08-26T12:22:05.395395+00:00","description":"\nAn issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is\nstarted with root privileges, the creation of the system.data file is prone\nto symlink attacks. The tss user can be used to create or corrupt existing\nfiles, which could possibly lead to a DoS attack.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"the Debian/Ubuntu package starts tcsd as the tss user, not as\nroot, so this issue doesn't affect default configurations"}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2020/08/14/1","https://seclists.org/oss-sec/2020/q2/att-135/tcsd_fixes.patch","https://sourceforge.net/p/trousers/mailman/message/37015817/","https://www.cve.org/CVERecord?id=CVE-2020-24332"],"bugs":["https://bugzilla.suse.com/show_bug.cgi?id=1164472"],"patches":{"trousers":[]},"tags":{},"packages":[{"name":"trousers","source":"https://ubuntu.com/security/cve?package=trousers","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=trousers","debian":"https://tracker.debian.org/pkg/trousers","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.3.15-0.2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-24331","published":"2020-08-13T17:15:00","updated_at":"2025-08-26T12:22:05.395395+00:00","description":"\nAn issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is\nstarted with root privileges, the tss user still has read and write access\nto the /etc/tcsd.conf file (which contains various settings related to this\ndaemon).","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"the Debian/Ubuntu package starts tcsd as the tss user, not as\nroot, so this issue doesn't affect default configurations"}],"codename":null,"priority":"negligible","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2020/08/14/1","https://seclists.org/oss-sec/2020/q2/att-135/tcsd_fixes.patch","https://sourceforge.net/p/trousers/mailman/message/37015817/","https://www.cve.org/CVERecord?id=CVE-2020-24331"],"bugs":["https://bugzilla.suse.com/show_bug.cgi?id=1164472"],"patches":{"trousers":[]},"tags":{},"packages":[{"name":"trousers","source":"https://ubuntu.com/security/cve?package=trousers","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=trousers","debian":"https://tracker.debian.org/pkg/trousers","statuses":[{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.3.15-0.2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-24330","published":"2020-08-13T17:15:00","updated_at":"2025-08-26T12:22:05.395395+00:00","description":"\nAn issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is\nstarted with root privileges instead of by the tss user, it fails to drop\nthe root gid privilege when no longer needed.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"the Debian/Ubuntu package starts tcsd as the tss user, not as\nroot, so this issue doesn't affect default configurations"}],"codename":null,"priority":"negligible","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2020/08/14/1","https://seclists.org/oss-sec/2020/q2/att-135/tcsd_fixes.patch","https://sourceforge.net/p/trousers/mailman/message/37015817/","https://www.cve.org/CVERecord?id=CVE-2020-24330"],"bugs":["https://bugzilla.suse.com/show_bug.cgi?id=1164472"],"patches":{"trousers":[]},"tags":{},"packages":[{"name":"trousers","source":"https://ubuntu.com/security/cve?package=trousers","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=trousers","debian":"https://tracker.debian.org/pkg/trousers","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.3.15-0.2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.3.15-0.3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-17498","published":"2020-08-13T16:15:00","updated_at":"2025-08-25T23:22:46.311482+00:00","description":"\nIn Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This\nwas addressed in epan/dissectors/packet-kafka.c by avoiding a double free\nduring LZ4 decompression.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16672","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=76afda963de4f0b9be24f2d8e873990a5cbf221b","https://www.wireshark.org/security/wnpa-sec-2020-10.html","https://ubuntu.com/security/notices/USN-6262-1","https://www.cve.org/CVERecord?id=CVE-2020-17498"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"focal","status":"released","description":"3.2.3-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"impish","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.2.6-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6262-1"],"notices":[{"id":"USN-6262-1","title":"Wireshark vulnerabilities","summary":"Several security issues were fixed in Wireshark.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-07-31T08:24:50.665134","description":"It was discovered that Wireshark did not properly handle certain\nNFS packages when certain configuration options were enabled.\nAn attacker could possibly use this issue to cause\nWireshark to crash, resulting in a denial of service. (CVE-2020-13164)\n\nIt was discovered that Wireshark did not properly handle certain GVCP\npackages. An attacker could possibly use this issue to cause\nWireshark to crash, resulting in a denial of service. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2020-15466)\n\nIt was discovered that Wireshark did not properly handle certain\nKafka packages. An attacker could possibly use this issue to cause\nWireshark to crash, resulting in a denial of service. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2020-17498)\n\nIt was discovered that Wireshark did not properly handle certain TCP\npackages containing an invalid 0xFFFF checksum. An attacker could\npossibly use this issue to cause Wireshark to crash, resulting in\na denial of service. (CVE-2020-25862)\n\nIt was discovered that Wireshark did not properly handle certain\nMIME packages containing invalid parts. An attacker could\npossibly use this issue to cause Wireshark to crash, resulting in\na denial of service. (CVE-2020-25863)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"wireshark","version":"2.6.10-1~ubuntu16.04.0+esm1","description":"network traffic analyzer - meta-package","is_source":true},{"name":"libwsutil-dev","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-dev","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"tshark","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-dev","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-qt","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap-dev","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-gtk","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwscodecs2","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-doc","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-common","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap8","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-data","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark11","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwsutil9","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"wireshark","version":"3.2.3-1ubuntu0.1~esm1","description":"network traffic analyzer - meta-package","is_source":true},{"name":"libwsutil-dev","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-dev","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"tshark","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-dev","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-qt","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap-dev","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwsutil11","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-doc","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap10","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-common","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-gtk","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-data","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark13","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"wireshark","version":"2.6.10-1~ubuntu18.04.0+esm1","description":"network traffic analyzer - meta-package","is_source":true},{"name":"libwsutil-dev","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-dev","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"tshark","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-dev","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-qt","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap-dev","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-gtk","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwscodecs2","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-doc","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-common","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap8","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-data","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark11","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwsutil9","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"wireshark","version":"2.6.10-1~ubuntu14.04.0~esm2","description":"network traffic analyzer - meta-package","is_source":true},{"name":"libwsutil-dev","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-dev","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"tshark","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwireshark-dev","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-qt","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwiretap-dev","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-gtk","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwscodecs2","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-doc","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-common","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwiretap8","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwireshark-data","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwireshark11","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwsutil9","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2020-13164","CVE-2020-17498","CVE-2020-15466","CVE-2020-25863","CVE-2020-25862"]}]},{"id":"CVE-2020-13286","published":"2020-08-13T14:15:00","updated_at":"2025-08-25T23:19:19.814270+00:00","description":"\nFor GitLab before 13.0.12, 13.1.6, 13.2.3 user controlled git configuration\nsettings can be modified to result in Server Side Request Forgery.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://about.gitlab.com/releases/2020/08/05/gitlab-13-2-3-released/","https://www.cve.org/CVERecord?id=CVE-2020-13286"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Only affects GitLab 12.7 and later","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-13281","published":"2020-08-13T14:15:00","updated_at":"2025-08-25T23:19:19.814270+00:00","description":"\nFor GitLab before 13.0.12, 13.1.6, 13.2.3 a denial of service exists in the\nproject import feature","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://about.gitlab.com/releases/2020/08/05/gitlab-13-2-3-released/","https://www.cve.org/CVERecord?id=CVE-2020-13281"],"bugs":[""],"patches":{"gitlab":[]},"tags":{},"packages":[{"name":"gitlab","source":"https://ubuntu.com/security/cve?package=gitlab","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gitlab","debian":"https://tracker.debian.org/pkg/gitlab","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":44820,"limit":20,"total_results":79316}