{"cves":[{"id":"CVE-2020-14928","published":"2020-07-08T00:00:00","updated_at":"2025-08-25T23:20:50.305513+00:00","description":"\nevolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue\nthat affects SMTP and POP3. When a server sends a \"begin TLS\" response, eds\nreads additional data and evaluates it in a TLS context, aka \"response\ninjection.\"","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-4429-1","https://www.cve.org/CVERecord?id=CVE-2020-14928"],"bugs":["https://gitlab.gnome.org/GNOME/evolution-data-server/-/issues/226"],"patches":{"evolution-data-server":["upstream: https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/f404f33fb01b23903c2bbb16791c7907e457fbac","upstream: https://gitlab.gnome.org/GNOME/evolution-data-server/-/commit/b74b765188d96803814acf69a510a7160d9ee6c5"]},"tags":{},"packages":[{"name":"evolution-data-server","source":"https://ubuntu.com/security/cve?package=evolution-data-server","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=evolution-data-server","debian":"https://tracker.debian.org/pkg/evolution-data-server","statuses":[{"release_codename":"focal","status":"released","description":"3.36.3-0ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"3.28.5-0ubuntu0.18.04.3","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.36.4-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.18.5-1ubuntu1.3","component":null,"pocket":"security"}]}],"notices_ids":["USN-4429-1"],"notices":[{"id":"USN-4429-1","title":"Evolution Data Server vulnerability","summary":"Evolution Data Server could be made to expose sensitive information over\nthe network.\n","instructions":"After a standard system update you need to restart your session to make\nall the necessary changes.\n","references":[],"published":"2020-07-22T12:03:30.251054","description":"It was discovered that Evolution Data Server incorrectly handled STARTTLS\nwhen using SMTP and POP3. A remote attacker could possibly use this issue\nto perform a response injection attack.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"evolution-data-server","version":"3.28.5-0ubuntu0.18.04.3","description":"Evolution suite data server","is_source":true},{"name":"evolution-data-server","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"evolution-data-server-common","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"evolution-data-server-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"evolution-data-server-doc","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"evolution-data-server-online-accounts","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"evolution-data-server-tests","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"gir1.2-camel-1.2","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"gir1.2-ebook-1.2","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"gir1.2-ebookcontacts-1.2","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"gir1.2-edataserver-1.2","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"gir1.2-edataserverui-1.2","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libcamel-1.2-61","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libcamel1.2-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libebackend-1.2-10","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libebackend1.2-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libebook-1.2-19","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libebook-contacts-1.2-2","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libebook-contacts1.2-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libebook1.2-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libecal-1.2-19","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libecal1.2-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libedata-book-1.2-25","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libedata-book1.2-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libedata-cal-1.2-28","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libedata-cal1.2-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libedataserver-1.2-23","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libedataserver1.2-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libedataserverui-1.2-2","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"},{"name":"libedataserverui1.2-dev","version":"3.28.5-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.3","pocket":"security"}],"focal":[{"name":"evolution-data-server","version":"3.36.3-0ubuntu1.1","description":"Evolution suite data server","is_source":true},{"name":"evolution-data-server","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"evolution-data-server-common","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"evolution-data-server-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"evolution-data-server-doc","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"evolution-data-server-tests","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"gir1.2-camel-1.2","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"gir1.2-ebackend-1.2","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"gir1.2-ebook-1.2","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"gir1.2-ebookcontacts-1.2","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"gir1.2-ecal-2.0","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"gir1.2-edatabook-1.2","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"gir1.2-edatacal-2.0","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"gir1.2-edataserver-1.2","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"gir1.2-edataserverui-1.2","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libcamel-1.2-62","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libcamel1.2-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libebackend-1.2-10","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libebackend1.2-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libebook-1.2-20","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libebook-contacts-1.2-3","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libebook-contacts1.2-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libebook1.2-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libecal-2.0-1","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libecal2.0-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libedata-book-1.2-26","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libedata-book1.2-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libedata-cal-2.0-1","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libedata-cal2.0-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libedataserver-1.2-24","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libedataserver1.2-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libedataserverui-1.2-2","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"},{"name":"libedataserverui1.2-dev","version":"3.36.3-0ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.36.3-0ubuntu1.1","pocket":"security"}],"xenial":[{"name":"evolution-data-server","version":"3.18.5-1ubuntu1.3","description":"Evolution suite data server","is_source":true},{"name":"evolution-data-server","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"evolution-data-server-common","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"evolution-data-server-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"evolution-data-server-doc","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"evolution-data-server-online-accounts","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"gir1.2-ebook-1.2","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"gir1.2-ebookcontacts-1.2","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"gir1.2-edataserver-1.2","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libcamel-1.2-54","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libcamel1.2-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libebackend-1.2-10","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libebackend1.2-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libebook-1.2-16","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libebook-contacts-1.2-2","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libebook-contacts1.2-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libebook1.2-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libecal-1.2-19","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libecal1.2-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libedata-book-1.2-25","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libedata-book1.2-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libedata-cal-1.2-28","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libedata-cal1.2-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libedataserver-1.2-21","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libedataserver1.2-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libedataserverui-1.2-1","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"},{"name":"libedataserverui1.2-dev","version":"3.18.5-1ubuntu1.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/evolution-data-server","version_link":"https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-14928"]}]},{"id":"CVE-2020-15095","published":"2020-07-07T19:15:00","updated_at":"2025-08-26T12:20:30.893186+00:00","description":"\nVersions of the npm CLI prior to 6.14.6 are vulnerable to an information\nexposure vulnerability through log files. The CLI supports URLs like\n\"<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>\". The\npassword value is not redacted and is printed to stdout and also to any\ngenerated log files.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/npm/cli/blob/66aab417f836a901f8afb265251f761bb0422463/CHANGELOG.md#6146-2020-07-07","https://github.com/npm/cli/commit/a9857b8f6869451ff058789c4631fadfde5bbcbc","https://github.com/npm/cli/security/advisories/GHSA-93f3-23rq-pjfp","https://www.cve.org/CVERecord?id=CVE-2020-15095"],"bugs":[""],"patches":{"npm":[]},"tags":{},"packages":[{"name":"npm","source":"https://ubuntu.com/security/cve?package=npm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=npm","debian":"https://tracker.debian.org/pkg/npm","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"6.14.6+ds-1ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-15567","published":"2020-07-07T13:15:00","updated_at":"2025-08-26T12:20:30.893186+00:00","description":"\nAn issue was discovered in Xen through 4.13.x, allowing Intel guest OS\nusers to gain privileges or cause a denial of service because of non-atomic\nmodification of a live EPT PTE. When mapping guest EPT (nested paging)\ntables, Xen would in some circumstances use a series of non-atomic bitfield\nwrites. Depending on the compiler version and optimisation flags, Xen might\nexpose a dangerous partially written PTE to the hardware, which an attacker\nmight be able to race to exploit. A guest administrator or perhaps even an\nunprivileged guest user might be able to cause denial of service, data\ncorruption, or privilege escalation. Only systems using Intel CPUs are\nvulnerable. Systems using AMD CPUs, and Arm systems, are not vulnerable.\nOnly systems using nested paging (hap, aka nested paging, aka in this case\nIntel EPT) are vulnerable. Only HVM and PVH guests can exploit the\nvulnerability. The presence and scope of the vulnerability depends on the\nprecise optimisations performed by the compiler used to build Xen. If the\ncompiler generates (a) a single 64-bit write, or (b) a series of\nread-modify-write operations in the same order as the source code, the\nhypervisor is not vulnerable. For example, in one test build using GCC 8.3\nwith normal settings, the compiler generated multiple (unlocked)\nread-modify-write operations in source-code order, which did not constitute\na vulnerability. We have not been able to survey compilers; consequently we\ncannot say which compiler(s) might produce vulnerable code (with which\ncode-generation options). The source code clearly violates the C rules, and\nthus should be considered vulnerable.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-328.html","http://www.openwall.com/lists/oss-security/2020/07/07/6","http://xenbits.xen.org/xsa/advisory-328.html","https://ubuntu.com/security/notices/USN-5617-1","https://www.cve.org/CVERecord?id=CVE-2020-15567"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5617-1"],"notices":[{"id":"USN-5617-1","title":"Xen vulnerabilities","summary":"Several security issues were fixed in Xen.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2022-09-19T16:56:10.295926","description":"It was discovered that memory contents previously stored in\nmicroarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY\nread operations on Intel client and Xeon E3 processors may be briefly\nexposed to processes on the same or different processor cores. A local\nattacker could use this to expose sensitive information. (CVE-2020-0543)\n\nJulien Grall discovered that Xen incorrectly handled memory barriers on\nARM-based systems. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information or escalate privileges.\n(CVE-2020-11739)\n\nIlja Van Sprundel discovered that Xen incorrectly handled profiling of\nguests. An unprivileged attacker could use this issue to obtain sensitive\ninformation from other guests, cause a denial of service or possibly gain\nprivileges. (CVE-2020-11740, CVE-2020-11741)\n\nIt was discovered that Xen incorrectly handled grant tables. A malicious\nguest could possibly use this issue to cause a denial of service.\n(CVE-2020-11742, CVE-2020-11743)\n\nJan Beulich discovered that Xen incorrectly handled certain code paths. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2020-15563)\n\nJulien Grall discovered that Xen incorrectly verified memory addresses\nprovided by the guest on ARM-based systems. A malicious guest administrator\ncould possibly use this issue to cause a denial of service. (CVE-2020-15564)\n\nRoger Pau Monné discovered that Xen incorrectly handled caching on x86 Intel\nsystems. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2020-15565)\n\nIt was discovered that Xen incorrectly handled error in event-channel port\nallocation. A malicious guest could possibly use this issue to cause a\ndenial of service. (CVE-2020-15566)\n\nJan Beulich discovered that Xen incorrectly handled certain EPT (Extended\nPage Tables).  An attacker could possibly use this issue to cause a denial\nof service, data corruption or privilege escalation. (CVE-2020-15567)\n\nAndrew Cooper discovered that Xen incorrectly handled PCI passthrough.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25595)\n\nAndrew Cooper discovered that Xen incorrectly sanitized path injections.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25596)\n\nJan Beulich discovered that Xen incorrectly handled validation of event\nchannels. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2020-25597)\n\nJulien Grall and Jan Beulich discovered that Xen incorrectly handled\nresetting event channels. An attacker could possibly use this issue to\ncause a denial of service or obtain sensitive information. (CVE-2020-25599)\n\nJulien Grall discovered that Xen incorrectly handled event channels\nmemory allocation on 32-bits domains. An attacker could possibly use this\nissue to cause a denial of service. (CVE-2020-25600)\n\nJan Beulich discovered that Xen incorrectly handled resetting or cleaning\nup event channels. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2020-25601)\n\nAndrew Cooper discovered that Xen incorrectly handled certain Intel\nspecific MSR (Model Specific Registers). An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2020-25602)\n\nJulien Grall discovered that Xen incorrectly handled accessing/allocating\nevent channels. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information of privilege escalation.\n(CVE-2020-25603)\n\nIgor Druzhinin discovered that Xen incorrectly handled locks. An attacker\ncould possibly use this issue to cause a denial of service. (CVE-2020-25604)\n","is_hidden":false,"release_packages":{"focal":[{"name":"xen","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","description":"Public headers and libs for Xen","is_source":true},{"name":"libxencall1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxengnttab1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoollog1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenstore3.0","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenmisc4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxendevicemodel1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xenstore-utils","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoolcore1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenforeignmemory1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-doc","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxen-dev","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenevtchn1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-25599","CVE-2020-11740","CVE-2020-11739","CVE-2020-15567","CVE-2020-15563","CVE-2020-25596","CVE-2020-25600","CVE-2020-25602","CVE-2020-11743","CVE-2020-11741","CVE-2020-15564","CVE-2020-0543","CVE-2020-15566","CVE-2020-15565","CVE-2020-25604","CVE-2020-25597","CVE-2020-25603","CVE-2020-25601","CVE-2020-25595","CVE-2020-11742"]}]},{"id":"CVE-2020-15566","published":"2020-07-07T13:15:00","updated_at":"2025-08-25T23:21:12.608839+00:00","description":"\nAn issue was discovered in Xen through 4.13.x, allowing guest OS users to\ncause a host OS crash because of incorrect error handling in event-channel\nport allocation. The allocation of an event-channel port may fail for\nmultiple reasons: (1) port is already in use, (2) the memory allocation\nfailed, or (3) the port we try to allocate is higher than what is supported\nby the ABI (e.g., 2L or FIFO) used by the guest or the limit set by an\nadministrator (max_event_channels in xl cfg). Due to the missing error\nchecks, only (1) will be considered an error. All the other cases will\nprovide a valid port and will result in a crash when trying to access the\nevent channel. When the administrator configured a guest to allow more than\n1023 event channels, that guest may be able to crash the host. When Xen is\nout-of-memory, allocation of new event channels will result in crashing the\nhost rather than reporting an error. Xen versions 4.10 and later are\naffected. All architectures are affected. The default configuration, when\nguests are created with xl/libxl, is not vulnerable, because of the default\nevent-channel limit.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-317.html","http://www.openwall.com/lists/oss-security/2020/07/07/2","http://xenbits.xen.org/xsa/advisory-317.html","https://ubuntu.com/security/notices/USN-5617-1","https://www.cve.org/CVERecord?id=CVE-2020-15566"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-5617-1"],"notices":[{"id":"USN-5617-1","title":"Xen vulnerabilities","summary":"Several security issues were fixed in Xen.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2022-09-19T16:56:10.295926","description":"It was discovered that memory contents previously stored in\nmicroarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY\nread operations on Intel client and Xeon E3 processors may be briefly\nexposed to processes on the same or different processor cores. A local\nattacker could use this to expose sensitive information. (CVE-2020-0543)\n\nJulien Grall discovered that Xen incorrectly handled memory barriers on\nARM-based systems. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information or escalate privileges.\n(CVE-2020-11739)\n\nIlja Van Sprundel discovered that Xen incorrectly handled profiling of\nguests. An unprivileged attacker could use this issue to obtain sensitive\ninformation from other guests, cause a denial of service or possibly gain\nprivileges. (CVE-2020-11740, CVE-2020-11741)\n\nIt was discovered that Xen incorrectly handled grant tables. A malicious\nguest could possibly use this issue to cause a denial of service.\n(CVE-2020-11742, CVE-2020-11743)\n\nJan Beulich discovered that Xen incorrectly handled certain code paths. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2020-15563)\n\nJulien Grall discovered that Xen incorrectly verified memory addresses\nprovided by the guest on ARM-based systems. A malicious guest administrator\ncould possibly use this issue to cause a denial of service. (CVE-2020-15564)\n\nRoger Pau Monné discovered that Xen incorrectly handled caching on x86 Intel\nsystems. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2020-15565)\n\nIt was discovered that Xen incorrectly handled error in event-channel port\nallocation. A malicious guest could possibly use this issue to cause a\ndenial of service. (CVE-2020-15566)\n\nJan Beulich discovered that Xen incorrectly handled certain EPT (Extended\nPage Tables).  An attacker could possibly use this issue to cause a denial\nof service, data corruption or privilege escalation. (CVE-2020-15567)\n\nAndrew Cooper discovered that Xen incorrectly handled PCI passthrough.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25595)\n\nAndrew Cooper discovered that Xen incorrectly sanitized path injections.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25596)\n\nJan Beulich discovered that Xen incorrectly handled validation of event\nchannels. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2020-25597)\n\nJulien Grall and Jan Beulich discovered that Xen incorrectly handled\nresetting event channels. An attacker could possibly use this issue to\ncause a denial of service or obtain sensitive information. (CVE-2020-25599)\n\nJulien Grall discovered that Xen incorrectly handled event channels\nmemory allocation on 32-bits domains. An attacker could possibly use this\nissue to cause a denial of service. (CVE-2020-25600)\n\nJan Beulich discovered that Xen incorrectly handled resetting or cleaning\nup event channels. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2020-25601)\n\nAndrew Cooper discovered that Xen incorrectly handled certain Intel\nspecific MSR (Model Specific Registers). An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2020-25602)\n\nJulien Grall discovered that Xen incorrectly handled accessing/allocating\nevent channels. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information of privilege escalation.\n(CVE-2020-25603)\n\nIgor Druzhinin discovered that Xen incorrectly handled locks. An attacker\ncould possibly use this issue to cause a denial of service. (CVE-2020-25604)\n","is_hidden":false,"release_packages":{"focal":[{"name":"xen","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","description":"Public headers and libs for Xen","is_source":true},{"name":"libxencall1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxengnttab1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoollog1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenstore3.0","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenmisc4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxendevicemodel1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xenstore-utils","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoolcore1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenforeignmemory1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-doc","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxen-dev","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenevtchn1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-25599","CVE-2020-11740","CVE-2020-11739","CVE-2020-15567","CVE-2020-15563","CVE-2020-25596","CVE-2020-25600","CVE-2020-25602","CVE-2020-11743","CVE-2020-11741","CVE-2020-15564","CVE-2020-0543","CVE-2020-15566","CVE-2020-15565","CVE-2020-25604","CVE-2020-25597","CVE-2020-25603","CVE-2020-25601","CVE-2020-25595","CVE-2020-11742"]}]},{"id":"CVE-2020-15565","published":"2020-07-07T13:15:00","updated_at":"2025-08-26T12:20:30.893186+00:00","description":"\nAn issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest\nOS users to cause a host OS denial of service or possibly gain privileges\nbecause of insufficient cache write-back under VT-d. When page tables are\nshared between IOMMU and CPU, changes to them require flushing of both\nTLBs. Furthermore, IOMMUs may be non-coherent, and hence prior to flushing\nIOMMU TLBs, a CPU cache also needs writing back to memory after changes\nwere made. Such writing back of cached data was missing in particular when\nsplitting large page mappings into smaller granularity ones. A malicious\nguest may be able to retain read/write DMA access to frames returned to\nXen's free pool, and later reused for another purpose. Host crashes\n(leading to a Denial of Service) and privilege escalation cannot be ruled\nout. Xen versions from at least 3.2 onwards are affected. Only x86 Intel\nsystems are affected. x86 AMD as well as Arm systems are not affected. Only\nx86 HVM guests using hardware assisted paging (HAP), having a passed\nthrough PCI device assigned, and having page table sharing enabled can\nleverage the vulnerability. Note that page table sharing will be enabled\n(by default) only if Xen considers IOMMU and CPU large page size support\ncompatible.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-321.html","http://www.openwall.com/lists/oss-security/2020/07/07/4","http://xenbits.xen.org/xsa/advisory-321.html","https://ubuntu.com/security/notices/USN-5617-1","https://www.cve.org/CVERecord?id=CVE-2020-15565"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-5617-1"],"notices":[{"id":"USN-5617-1","title":"Xen vulnerabilities","summary":"Several security issues were fixed in Xen.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2022-09-19T16:56:10.295926","description":"It was discovered that memory contents previously stored in\nmicroarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY\nread operations on Intel client and Xeon E3 processors may be briefly\nexposed to processes on the same or different processor cores. A local\nattacker could use this to expose sensitive information. (CVE-2020-0543)\n\nJulien Grall discovered that Xen incorrectly handled memory barriers on\nARM-based systems. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information or escalate privileges.\n(CVE-2020-11739)\n\nIlja Van Sprundel discovered that Xen incorrectly handled profiling of\nguests. An unprivileged attacker could use this issue to obtain sensitive\ninformation from other guests, cause a denial of service or possibly gain\nprivileges. (CVE-2020-11740, CVE-2020-11741)\n\nIt was discovered that Xen incorrectly handled grant tables. A malicious\nguest could possibly use this issue to cause a denial of service.\n(CVE-2020-11742, CVE-2020-11743)\n\nJan Beulich discovered that Xen incorrectly handled certain code paths. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2020-15563)\n\nJulien Grall discovered that Xen incorrectly verified memory addresses\nprovided by the guest on ARM-based systems. A malicious guest administrator\ncould possibly use this issue to cause a denial of service. (CVE-2020-15564)\n\nRoger Pau Monné discovered that Xen incorrectly handled caching on x86 Intel\nsystems. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2020-15565)\n\nIt was discovered that Xen incorrectly handled error in event-channel port\nallocation. A malicious guest could possibly use this issue to cause a\ndenial of service. (CVE-2020-15566)\n\nJan Beulich discovered that Xen incorrectly handled certain EPT (Extended\nPage Tables).  An attacker could possibly use this issue to cause a denial\nof service, data corruption or privilege escalation. (CVE-2020-15567)\n\nAndrew Cooper discovered that Xen incorrectly handled PCI passthrough.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25595)\n\nAndrew Cooper discovered that Xen incorrectly sanitized path injections.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25596)\n\nJan Beulich discovered that Xen incorrectly handled validation of event\nchannels. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2020-25597)\n\nJulien Grall and Jan Beulich discovered that Xen incorrectly handled\nresetting event channels. An attacker could possibly use this issue to\ncause a denial of service or obtain sensitive information. (CVE-2020-25599)\n\nJulien Grall discovered that Xen incorrectly handled event channels\nmemory allocation on 32-bits domains. An attacker could possibly use this\nissue to cause a denial of service. (CVE-2020-25600)\n\nJan Beulich discovered that Xen incorrectly handled resetting or cleaning\nup event channels. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2020-25601)\n\nAndrew Cooper discovered that Xen incorrectly handled certain Intel\nspecific MSR (Model Specific Registers). An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2020-25602)\n\nJulien Grall discovered that Xen incorrectly handled accessing/allocating\nevent channels. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information of privilege escalation.\n(CVE-2020-25603)\n\nIgor Druzhinin discovered that Xen incorrectly handled locks. An attacker\ncould possibly use this issue to cause a denial of service. (CVE-2020-25604)\n","is_hidden":false,"release_packages":{"focal":[{"name":"xen","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","description":"Public headers and libs for Xen","is_source":true},{"name":"libxencall1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxengnttab1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoollog1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenstore3.0","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenmisc4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxendevicemodel1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xenstore-utils","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoolcore1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenforeignmemory1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-doc","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxen-dev","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenevtchn1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-25599","CVE-2020-11740","CVE-2020-11739","CVE-2020-15567","CVE-2020-15563","CVE-2020-25596","CVE-2020-25600","CVE-2020-25602","CVE-2020-11743","CVE-2020-11741","CVE-2020-15564","CVE-2020-0543","CVE-2020-15566","CVE-2020-15565","CVE-2020-25604","CVE-2020-25597","CVE-2020-25603","CVE-2020-25601","CVE-2020-25595","CVE-2020-11742"]}]},{"id":"CVE-2020-15564","published":"2020-07-07T13:15:00","updated_at":"2025-08-26T12:20:30.893186+00:00","description":"\nAn issue was discovered in Xen through 4.13.x, allowing Arm guest OS users\nto cause a hypervisor crash because of a missing alignment check in\nVCPUOP_register_vcpu_info. The hypercall VCPUOP_register_vcpu_info is used\nby a guest to register a shared region with the hypervisor. The region will\nbe mapped into Xen address space so it can be directly accessed. On Arm,\nthe region is accessed with instructions that require a specific alignment.\nUnfortunately, there is no check that the address provided by the guest\nwill be correctly aligned. As a result, a malicious guest could cause a\nhypervisor crash by passing a misaligned address. A malicious guest\nadministrator may cause a hypervisor crash, resulting in a Denial of\nService (DoS). All Xen versions are vulnerable. Only Arm systems are\nvulnerable. x86 systems are not affected.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-327.html","http://www.openwall.com/lists/oss-security/2020/07/07/5","http://xenbits.xen.org/xsa/advisory-327.html","https://ubuntu.com/security/notices/USN-5617-1","https://www.cve.org/CVERecord?id=CVE-2020-15564"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-5617-1"],"notices":[{"id":"USN-5617-1","title":"Xen vulnerabilities","summary":"Several security issues were fixed in Xen.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2022-09-19T16:56:10.295926","description":"It was discovered that memory contents previously stored in\nmicroarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY\nread operations on Intel client and Xeon E3 processors may be briefly\nexposed to processes on the same or different processor cores. A local\nattacker could use this to expose sensitive information. (CVE-2020-0543)\n\nJulien Grall discovered that Xen incorrectly handled memory barriers on\nARM-based systems. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information or escalate privileges.\n(CVE-2020-11739)\n\nIlja Van Sprundel discovered that Xen incorrectly handled profiling of\nguests. An unprivileged attacker could use this issue to obtain sensitive\ninformation from other guests, cause a denial of service or possibly gain\nprivileges. (CVE-2020-11740, CVE-2020-11741)\n\nIt was discovered that Xen incorrectly handled grant tables. A malicious\nguest could possibly use this issue to cause a denial of service.\n(CVE-2020-11742, CVE-2020-11743)\n\nJan Beulich discovered that Xen incorrectly handled certain code paths. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2020-15563)\n\nJulien Grall discovered that Xen incorrectly verified memory addresses\nprovided by the guest on ARM-based systems. A malicious guest administrator\ncould possibly use this issue to cause a denial of service. (CVE-2020-15564)\n\nRoger Pau Monné discovered that Xen incorrectly handled caching on x86 Intel\nsystems. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2020-15565)\n\nIt was discovered that Xen incorrectly handled error in event-channel port\nallocation. A malicious guest could possibly use this issue to cause a\ndenial of service. (CVE-2020-15566)\n\nJan Beulich discovered that Xen incorrectly handled certain EPT (Extended\nPage Tables).  An attacker could possibly use this issue to cause a denial\nof service, data corruption or privilege escalation. (CVE-2020-15567)\n\nAndrew Cooper discovered that Xen incorrectly handled PCI passthrough.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25595)\n\nAndrew Cooper discovered that Xen incorrectly sanitized path injections.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25596)\n\nJan Beulich discovered that Xen incorrectly handled validation of event\nchannels. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2020-25597)\n\nJulien Grall and Jan Beulich discovered that Xen incorrectly handled\nresetting event channels. An attacker could possibly use this issue to\ncause a denial of service or obtain sensitive information. (CVE-2020-25599)\n\nJulien Grall discovered that Xen incorrectly handled event channels\nmemory allocation on 32-bits domains. An attacker could possibly use this\nissue to cause a denial of service. (CVE-2020-25600)\n\nJan Beulich discovered that Xen incorrectly handled resetting or cleaning\nup event channels. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2020-25601)\n\nAndrew Cooper discovered that Xen incorrectly handled certain Intel\nspecific MSR (Model Specific Registers). An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2020-25602)\n\nJulien Grall discovered that Xen incorrectly handled accessing/allocating\nevent channels. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information of privilege escalation.\n(CVE-2020-25603)\n\nIgor Druzhinin discovered that Xen incorrectly handled locks. An attacker\ncould possibly use this issue to cause a denial of service. (CVE-2020-25604)\n","is_hidden":false,"release_packages":{"focal":[{"name":"xen","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","description":"Public headers and libs for Xen","is_source":true},{"name":"libxencall1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxengnttab1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoollog1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenstore3.0","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenmisc4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxendevicemodel1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xenstore-utils","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoolcore1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenforeignmemory1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-doc","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxen-dev","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenevtchn1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-25599","CVE-2020-11740","CVE-2020-11739","CVE-2020-15567","CVE-2020-15563","CVE-2020-25596","CVE-2020-25600","CVE-2020-25602","CVE-2020-11743","CVE-2020-11741","CVE-2020-15564","CVE-2020-0543","CVE-2020-15566","CVE-2020-15565","CVE-2020-25604","CVE-2020-25597","CVE-2020-25603","CVE-2020-25601","CVE-2020-25595","CVE-2020-11742"]}]},{"id":"CVE-2020-15563","published":"2020-07-07T13:15:00","updated_at":"2025-08-25T23:21:12.608839+00:00","description":"\nAn issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS\nusers to cause a hypervisor crash. An inverted conditional in x86 HVM\nguests' dirty video RAM tracking code allows such guests to make Xen\nde-reference a pointer guaranteed to point at unmapped space. A malicious\nor buggy HVM guest may cause the hypervisor to crash, resulting in Denial\nof Service (DoS) affecting the entire host. Xen versions from 4.8 onwards\nare affected. Xen versions 4.7 and earlier are not affected. Only x86\nsystems are affected. Arm systems are not affected. Only x86 HVM guests\nusing shadow paging can leverage the vulnerability. In addition, there\nneeds to be an entity actively monitoring a guest's video frame buffer\n(typically for display purposes) in order for such a guest to be able to\nleverage the vulnerability. x86 PV guests, as well as x86 HVM guests using\nhardware assisted paging (HAP), cannot leverage the vulnerability.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"hypervisor packages are in universe. For\nissues in the hypervisor, add appropriate\ntags to each section, ex:\nTags_xen: universe-binary"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://xenbits.xen.org/xsa/advisory-319.html","http://www.openwall.com/lists/oss-security/2020/07/07/3","http://xenbits.xen.org/xsa/advisory-319.html","https://ubuntu.com/security/notices/USN-5617-1","https://www.cve.org/CVERecord?id=CVE-2020-15563"],"bugs":[""],"patches":{"xen":[]},"tags":{"xen":["universe-binary"]},"packages":[{"name":"xen","source":"https://ubuntu.com/security/cve?package=xen","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xen","debian":"https://tracker.debian.org/pkg/xen","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.11.4+24-gddaaccbbab-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-5617-1"],"notices":[{"id":"USN-5617-1","title":"Xen vulnerabilities","summary":"Several security issues were fixed in Xen.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n","references":[],"published":"2022-09-19T16:56:10.295926","description":"It was discovered that memory contents previously stored in\nmicroarchitectural special registers after RDRAND, RDSEED, and SGX EGETKEY\nread operations on Intel client and Xeon E3 processors may be briefly\nexposed to processes on the same or different processor cores. A local\nattacker could use this to expose sensitive information. (CVE-2020-0543)\n\nJulien Grall discovered that Xen incorrectly handled memory barriers on\nARM-based systems. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information or escalate privileges.\n(CVE-2020-11739)\n\nIlja Van Sprundel discovered that Xen incorrectly handled profiling of\nguests. An unprivileged attacker could use this issue to obtain sensitive\ninformation from other guests, cause a denial of service or possibly gain\nprivileges. (CVE-2020-11740, CVE-2020-11741)\n\nIt was discovered that Xen incorrectly handled grant tables. A malicious\nguest could possibly use this issue to cause a denial of service.\n(CVE-2020-11742, CVE-2020-11743)\n\nJan Beulich discovered that Xen incorrectly handled certain code paths. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2020-15563)\n\nJulien Grall discovered that Xen incorrectly verified memory addresses\nprovided by the guest on ARM-based systems. A malicious guest administrator\ncould possibly use this issue to cause a denial of service. (CVE-2020-15564)\n\nRoger Pau Monné discovered that Xen incorrectly handled caching on x86 Intel\nsystems. An attacker could possibly use this issue to cause a denial of\nservice. (CVE-2020-15565)\n\nIt was discovered that Xen incorrectly handled error in event-channel port\nallocation. A malicious guest could possibly use this issue to cause a\ndenial of service. (CVE-2020-15566)\n\nJan Beulich discovered that Xen incorrectly handled certain EPT (Extended\nPage Tables).  An attacker could possibly use this issue to cause a denial\nof service, data corruption or privilege escalation. (CVE-2020-15567)\n\nAndrew Cooper discovered that Xen incorrectly handled PCI passthrough.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25595)\n\nAndrew Cooper discovered that Xen incorrectly sanitized path injections.\nAn attacker could possibly use this issue to cause a denial of service.\n(CVE-2020-25596)\n\nJan Beulich discovered that Xen incorrectly handled validation of event\nchannels. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2020-25597)\n\nJulien Grall and Jan Beulich discovered that Xen incorrectly handled\nresetting event channels. An attacker could possibly use this issue to\ncause a denial of service or obtain sensitive information. (CVE-2020-25599)\n\nJulien Grall discovered that Xen incorrectly handled event channels\nmemory allocation on 32-bits domains. An attacker could possibly use this\nissue to cause a denial of service. (CVE-2020-25600)\n\nJan Beulich discovered that Xen incorrectly handled resetting or cleaning\nup event channels. An attacker could possibly use this issue to cause a\ndenial of service. (CVE-2020-25601)\n\nAndrew Cooper discovered that Xen incorrectly handled certain Intel\nspecific MSR (Model Specific Registers). An attacker could possibly use\nthis issue to cause a denial of service. (CVE-2020-25602)\n\nJulien Grall discovered that Xen incorrectly handled accessing/allocating\nevent channels. An attacker could possibly use this issue to cause a\ndenial of service, obtain sensitive information of privilege escalation.\n(CVE-2020-25603)\n\nIgor Druzhinin discovered that Xen incorrectly handled locks. An attacker\ncould possibly use this issue to cause a denial of service. (CVE-2020-25604)\n","is_hidden":false,"release_packages":{"focal":[{"name":"xen","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","description":"Public headers and libs for Xen","is_source":true},{"name":"libxencall1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxengnttab1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoollog1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenstore3.0","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenmisc4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxendevicemodel1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xenstore-utils","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxentoolcore1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-4.11","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenforeignmemory1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-doc","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-amd64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.11-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-4.9-arm64","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-utils-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxen-dev","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-hypervisor-common","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"libxenevtchn1","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"},{"name":"xen-system-armhf","version":"4.11.3+24-g14b62ab3e5-1ubuntu2.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/xen","version_link":"https://launchpad.net/ubuntu/+source/xen/4.11.3+24-g14b62ab3e5-1ubuntu2.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-25599","CVE-2020-11740","CVE-2020-11739","CVE-2020-15567","CVE-2020-15563","CVE-2020-25596","CVE-2020-25600","CVE-2020-25602","CVE-2020-11743","CVE-2020-11741","CVE-2020-15564","CVE-2020-0543","CVE-2020-15566","CVE-2020-15565","CVE-2020-25604","CVE-2020-25597","CVE-2020-25603","CVE-2020-25601","CVE-2020-25595","CVE-2020-11742"]}]},{"id":"CVE-2020-14303","published":"2020-07-06T18:15:00","updated_at":"2025-08-25T23:20:25.447625+00:00","description":"\nA flaw was found in the AD DC NBT server in all Samba versions before\n4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty\nUDP packet to cause the samba server to crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.samba.org/samba/security/CVE-2020-14303.html","https://ubuntu.com/security/notices/USN-4454-1","https://ubuntu.com/security/notices/USN-4454-2","https://www.cve.org/CVERecord?id=CVE-2020-14303"],"bugs":["https://bugzilla.samba.org/show_bug.cgi?id=14417"],"patches":{"samba":["upstream: https://github.com/samba-team/samba/commit/3cc0f1eeda5f133532dda31eef9fc1b394127e50"]},"tags":{},"packages":[{"name":"samba","source":"https://ubuntu.com/security/cve?package=samba","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=samba","debian":"https://tracker.debian.org/pkg/samba","statuses":[{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"2:4.3.11+dfsg-0ubuntu0.16.04.29","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2:4.11.6+dfsg-0ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-4454-1","USN-4454-2"],"notices":[{"id":"USN-4454-1","title":"Samba vulnerability","summary":"Samba could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-08-10T13:42:33.948487","description":"Martin von Wittich and Wilko Meyer discovered that Samba incorrectly\nhandled certain empty UDP packets when being used as a AD DC NBT server. A\nremote attacker could possibly use this issue to cause Samba to crash,\nresulting in a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"samba","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"ctdb","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"libnss-winbind","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"libpam-winbind","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"libsmbclient","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"libwbclient0","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"python-samba","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"registry-tools","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"samba","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"samba-common","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"samba-common-bin","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"samba-dev","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"samba-libs","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"samba-testsuite","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"smbclient","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"},{"name":"winbind","version":"2:4.7.6+dfsg~ubuntu-0ubuntu2.18","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.7.6+dfsg~ubuntu-0ubuntu2.18","pocket":"security"}],"focal":[{"name":"samba","version":"2:4.11.6+dfsg-0ubuntu1.4","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"ctdb","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"libnss-winbind","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"libpam-winbind","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"libsmbclient","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"libwbclient0","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"python3-samba","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"registry-tools","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"samba","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"samba-common","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"samba-common-bin","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"samba-dev","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"samba-libs","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"samba-testsuite","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"smbclient","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"},{"name":"winbind","version":"2:4.11.6+dfsg-0ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.11.6+dfsg-0ubuntu1.4","pocket":"security"}],"xenial":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"ctdb","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.16.04.29","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.16.04.29","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-14303"]},{"id":"USN-4454-2","title":"Samba vulnerability","summary":"Samba could be made to crash if it received specially crafted network\ntraffic.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-08-10T19:10:54.189530","description":"USN-4454-1 fixed a vulnerability in Samba. This update provides\nthe corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.\n\nOriginal advisory details:\n\n Martin von Wittich and Wilko Meyer discovered that Samba incorrectly\n handled certain empty UDP packets when being used as a AD DC NBT server. A\n remote attacker could possibly use this issue to cause Samba to crash,\n resulting in a denial of service.\n","is_hidden":false,"release_packages":{"precise":[{"name":"samba","version":"2:3.6.25-0ubuntu0.12.04.21","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libwbclient-dev","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"samba","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"swat","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"samba-doc","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"libpam-winbind","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"libsmbclient","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"smbclient","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"samba-tools","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"winbind","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"samba-common-bin","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"libwbclient0","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"libpam-smbpass","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"libsmbclient-dev","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"samba-doc-pdf","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"},{"name":"samba-common","version":"2:3.6.25-0ubuntu0.12.04.21","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:3.6.25-0ubuntu0.12.04.21"}],"trusty":[{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","description":"SMB/CIFS file, print, and login server for Unix","is_source":true},{"name":"libnss-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"libpam-winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"libwbclient0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"samba-common","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"samba-libs","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"libsmbsharemodes0","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"samba-testsuite","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"libsmbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"samba-common-bin","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"libsmbsharemodes-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"python-samba","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"winbind","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"smbclient","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"samba-vfs-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"libwbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"samba-dsdb-modules","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"samba-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"libsmbclient-dev","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"libparse-pidl-perl","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"registry-tools","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"samba-doc","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"},{"name":"libpam-smbpass","version":"2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/samba","version_link":"https://launchpad.net/ubuntu/+source/samba/2:4.3.11+dfsg-0ubuntu0.14.04.20+esm8"}]},"type":"USN","cves_ids":["CVE-2020-14303"]}]},{"id":"CVE-2020-15570","published":"2020-07-06T14:15:00","updated_at":"2025-08-25T23:21:12.608839+00:00","description":"\nThe parse_report() function in whoopsie.c in Whoopsie through 0.2.69\nmishandles memory allocation failures, which allows an attacker to cause a\ndenial of service via a malformed crash file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/sungjungk/whoopsie_killer2/blob/master/README.md","https://github.com/sungjungk/whoopsie_killer2/blob/master/whoopsie_killer2.py","https://launchpad.net/ubuntu/+source/whoopsie","https://www.youtube.com/watch?v=oZXGwC7PWYE","https://ubuntu.com/security/notices/USN-4450-1","https://www.cve.org/CVERecord?id=CVE-2020-15570"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/whoopsie/+bug/1882180"],"patches":{"whoopsie":[]},"tags":{},"packages":[{"name":"whoopsie","source":"https://ubuntu.com/security/cve?package=whoopsie","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=whoopsie","debian":"https://tracker.debian.org/pkg/whoopsie","statuses":[{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.2.62ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.2.69ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"0.2.52.5ubuntu0.5","component":null,"pocket":"security"}]}],"notices_ids":["USN-4450-1"],"notices":[{"id":"USN-4450-1","title":"Whoopsie vulnerabilities","summary":"Several security issues were fixed in whoopsie.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-08-04T17:14:50.507293","description":"Seong-Joong Kim discovered that Whoopsie incorrectly handled memory. A\nlocal attacker could use this issue to cause Whoopsie to consume memory,\nresulting in a denial of service. (CVE-2020-11937)\n\nSeong-Joong Kim discovered that Whoopsie incorrectly handled parsing files.\nA local attacker could use this issue to cause Whoopsie to crash, resulting\nin a denial of service, or possibly execute arbitrary code.\n(CVE-2020-12135)\n\nSeong-Joong Kim discovered that Whoopsie incorrectly handled memory. A\nlocal attacker could use this issue to cause Whoopsie to consume memory,\nresulting in a denial of service. (CVE-2020-15570)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"whoopsie","version":"0.2.62ubuntu0.5","description":"Ubuntu error tracker submission","is_source":true},{"name":"libwhoopsie-dev","version":"0.2.62ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/whoopsie","version_link":"https://launchpad.net/ubuntu/+source/whoopsie/0.2.62ubuntu0.5","pocket":"security"},{"name":"libwhoopsie0","version":"0.2.62ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/whoopsie","version_link":"https://launchpad.net/ubuntu/+source/whoopsie/0.2.62ubuntu0.5","pocket":"security"},{"name":"whoopsie","version":"0.2.62ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/whoopsie","version_link":"https://launchpad.net/ubuntu/+source/whoopsie/0.2.62ubuntu0.5","pocket":"security"}],"focal":[{"name":"whoopsie","version":"0.2.69ubuntu0.1","description":"Ubuntu error tracker submission","is_source":true},{"name":"libwhoopsie-dev","version":"0.2.69ubuntu0.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/whoopsie","version_link":"https://launchpad.net/ubuntu/+source/whoopsie/0.2.69ubuntu0.1","pocket":"security"},{"name":"libwhoopsie0","version":"0.2.69ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/whoopsie","version_link":"https://launchpad.net/ubuntu/+source/whoopsie/0.2.69ubuntu0.1","pocket":"security"},{"name":"whoopsie","version":"0.2.69ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/whoopsie","version_link":"https://launchpad.net/ubuntu/+source/whoopsie/0.2.69ubuntu0.1","pocket":"security"}],"xenial":[{"name":"whoopsie","version":"0.2.52.5ubuntu0.5","description":"Ubuntu error tracker submission","is_source":true},{"name":"libwhoopsie-dev","version":"0.2.52.5ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/whoopsie","version_link":"https://launchpad.net/ubuntu/+source/whoopsie/0.2.52.5ubuntu0.5","pocket":"security"},{"name":"libwhoopsie0","version":"0.2.52.5ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/whoopsie","version_link":"https://launchpad.net/ubuntu/+source/whoopsie/0.2.52.5ubuntu0.5","pocket":"security"},{"name":"whoopsie","version":"0.2.52.5ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/whoopsie","version_link":"https://launchpad.net/ubuntu/+source/whoopsie/0.2.52.5ubuntu0.5","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-11937","CVE-2020-12135","CVE-2020-15570"]}]},{"id":"CVE-2020-15569","published":"2020-07-06T14:15:00","updated_at":"2025-08-26T12:20:30.893186+00:00","description":"\nPlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in\nthe PlayerGeneric destructor.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/milkytracker/MilkyTracker/commit/7afd55c42ad80d01a339197a2d8b5461d214edaf","https://www.cve.org/CVERecord?id=CVE-2020-15569"],"bugs":[""],"patches":{"milkytracker":[]},"tags":{},"packages":[{"name":"milkytracker","source":"https://ubuntu.com/security/cve?package=milkytracker","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=milkytracker","debian":"https://tracker.debian.org/pkg/milkytracker","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.02.00+dfsg-2.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-15562","published":"2020-07-06T12:15:00","updated_at":"2025-08-25T23:21:12.608839+00:00","description":"\nAn issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before\n1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail\nmessage, as demonstrated by a JavaScript payload in the xmlns (aka XML\nnamespace) attribute of a HEAD element when an SVG element exists.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/roundcube/roundcubemail/commit/3e8832d029b035e3fcfb4c75839567a9580b4f82","https://github.com/roundcube/roundcubemail/releases/tag/1.2.11","https://github.com/roundcube/roundcubemail/releases/tag/1.3.14","https://github.com/roundcube/roundcubemail/releases/tag/1.4.7","https://ubuntu.com/security/notices/USN-5182-1","https://www.cve.org/CVERecord?id=CVE-2020-15562"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=964355"],"patches":{"roundcube":["upstream: https://github.com/roundcube/roundcubemail/commit/f3d1566cf223eb04f47b6dfffcd88753f66c36ee","upstream: https://github.com/roundcube/roundcubemail/commit/19502419757a976dbd55ce5a746610c5bab7896b","upstream: https://github.com/roundcube/roundcubemail/commit/3e8832d029b035e3fcfb4c75839567a9580b4f82"]},"tags":{},"packages":[{"name":"roundcube","source":"https://ubuntu.com/security/cve?package=roundcube","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=roundcube","debian":"https://tracker.debian.org/pkg/roundcube","statuses":[{"release_codename":"impish","status":"not-affected","description":"1.4.11+dfsg.1-4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.11, 1.3.14, 1.4.7","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.4.7+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.3.6+dfsg.1-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.4.3+dfsg.1-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.4.7+dfsg.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.5.0+dfsg.1-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.5.0+dfsg.1-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.5.0+dfsg.1-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.5.0+dfsg.1-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.5.0+dfsg.1-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.5.0+dfsg.1-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.5.0+dfsg.1-2","component":null,"pocket":"security"}]}],"notices_ids":["USN-5182-1"],"notices":[{"id":"USN-5182-1","title":"Roundcube Webmail vulnerabilities","summary":"Several security issues were fixed in Roundcube Webmail.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-08-08T06:30:29.641028","description":"It was discovered that Roundcube Webmail allowed JavaScript code to be present\nin the CDATA of an HTML message. A remote attacker could possibly use this\nissue to execute a cross-site scripting (XSS) attack. This issue only affected\nUbuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-12625)\n\nIt was discovered that Roundcube Webmail incorrectly processed login and\nlogout POST requests. An attacker could possibly use this issue to launch a\ncross-site request forgery (CSRF) attack and force an authenticated user to be\nlogged out. This issue only affected Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and\nUbuntu 20.04 ESM. (CVE-2020-12626)\n\nIt was discovered that Roundcube Webmail incorrectly processed new plugin names\nin rcube_plugin_api.php. An attacker could possibly use this issue to obtain\nsensitive information from local files or to execute arbitrary code.\nThis issue only affected Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and\nUbuntu 20.04 ESM. (CVE-2020-12640)\n\nIt was discovered that Roundcube Webmail did not sanitize shell metacharacters\nrecovered from variables in its configuration settings. An attacker could\npossibly use this issue to execute arbitrary code in the server. This issue\nonly affected Ubuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM.\n(CVE-2020-12641)\n\nIt was discovered that Roundcube Webmail incorrectly sanitized characters in\nthe username template object. An attacker could possibly use this issue to\nexecute a cross-site scripting (XSS) attack. This issue only affected\nUbuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-13964)\n\nIt was discovered that Roundcube Webmail allowed preview of text/html content.\nA remote attacker could possibly use this issue to send a malicious XML\nattachment via an email message and execute a cross-site scripting (XSS)\nattack. This issue only affected Ubuntu 16.04 ESM, Ubuntu 18.04 ESM\nand Ubuntu 20.04 ESM. (CVE-2020-13965)\n\nAndrea Cardaci discovered that Roundcube Webmail did not properly sanitize\nHTML special characters when dealing with HTML messages that contained an SVG\nelement in the XML namespace. A remote attacker could possibly use this issue\nto execute a cross-site scripting (XSS) attack. This issue only affected\nUbuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-15562)\n\nLukasz Pilorz discovered that Roundcube Webmail did not properly sanitize HTML\nspecial characters when dealing with HTML messages that contained SVG\ndocuments. A remote attacker could possibly use this issue to execute a\ncross-site scripting (XSS) attack. This issue only affected Ubuntu 18.04 ESM\nand Ubuntu 20.04 ESM. (CVE-2020-16145)\n\nAlex Birnberg discovered that Roundcube Webmail incorrectly sanitized\ncharacters in plain text e-mail messages that included link reference\nelements. A remote attacker could possibly use this issue to execute a\ncross-site scripting (XSS) attack. This issue only affected Ubuntu 16.04 ESM,\nUbuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2020-35730)\n\nIt was discovered that Roundcube Webmail did not properly sanitize HTML\nspecial characters in warning messages that contained an attachment's filename\nextension. A remote attacker could possibly use this issue to execute a\ncross-site scripting (XSS) attack. This issue only affected Ubuntu 16.04 ESM,\nUbuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-44025)\n\nIt was discovered that Roundcube Webmail incorrectly managed session variables\nrelated to search functionalities. A remote attacker could possibly use this\nissue to execute a SQL injection attack. This issue only affected\nUbuntu 16.04 ESM, Ubuntu 18.04 ESM and Ubuntu 20.04 ESM. (CVE-2021-44026)\n\nIt was discovered that Roundcube Webmail did not properly sanitize HTML\nspecial characters when dealing with HTML messages that contained CSS content.\nA remote attacker could possibly use this issue to execute a cross-site\nscripting (XSS) attack. This issue only affected Ubuntu 18.04 ESM,\nUbuntu 20.04 ESM and Ubuntu 22.04 ESM. (CVE-2021-46144)\n","is_hidden":false,"release_packages":{"jammy":[{"name":"roundcube","version":"1.5.0+dfsg.1-2ubuntu0.1~esm1","description":"skinnable AJAX based webmail solution for IMAP servers - metapack","is_source":true},{"name":"roundcube-pgsql","version":"1.5.0+dfsg.1-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-mysql","version":"1.5.0+dfsg.1-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-plugins","version":"1.5.0+dfsg.1-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube","version":"1.5.0+dfsg.1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-core","version":"1.5.0+dfsg.1-2ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-sqlite3","version":"1.5.0+dfsg.1-2ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"roundcube","version":"1.4.3+dfsg.1-1ubuntu0.1~esm2","description":"skinnable AJAX based webmail solution for IMAP servers - metapack","is_source":true},{"name":"roundcube-pgsql","version":"1.4.3+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-mysql","version":"1.4.3+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-plugins","version":"1.4.3+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube","version":"1.4.3+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-core","version":"1.4.3+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-sqlite3","version":"1.4.3+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"roundcube","version":"1.3.6+dfsg.1-1ubuntu0.1~esm2","description":"skinnable AJAX based webmail solution for IMAP servers - metapack","is_source":true},{"name":"roundcube-pgsql","version":"1.3.6+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-mysql","version":"1.3.6+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-plugins","version":"1.3.6+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube","version":"1.3.6+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-core","version":"1.3.6+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-sqlite3","version":"1.3.6+dfsg.1-1ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"}],"xenial":[{"name":"roundcube","version":"1.2~beta+dfsg.1-0ubuntu1+esm2","description":"skinnable AJAX based webmail solution for IMAP servers - metapack","is_source":true},{"name":"roundcube-pgsql","version":"1.2~beta+dfsg.1-0ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-mysql","version":"1.2~beta+dfsg.1-0ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-plugins","version":"1.2~beta+dfsg.1-0ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube","version":"1.2~beta+dfsg.1-0ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-core","version":"1.2~beta+dfsg.1-0ubuntu1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"},{"name":"roundcube-sqlite3","version":"1.2~beta+dfsg.1-0ubuntu1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/roundcube","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2020-13964","CVE-2020-13965","CVE-2021-44026","CVE-2021-46144","CVE-2020-12626","CVE-2020-12641","CVE-2020-35730","CVE-2020-12625","CVE-2020-12640","CVE-2020-15562","CVE-2020-16145","CVE-2021-44025"]}]},{"id":"CVE-2020-15466","published":"2020-07-05T11:15:00","updated_at":"2025-08-25T23:21:08.095624+00:00","description":"\nIn Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite\nloop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that\nan offset increases in all situations.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=16029","https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=11f40896b696e4e8c7f8b2ad96028404a83a51a4","https://www.wireshark.org/security/wnpa-sec-2020-09.html","https://ubuntu.com/security/notices/USN-6262-1","https://www.cve.org/CVERecord?id=CVE-2020-15466"],"bugs":[""],"patches":{"wireshark":[]},"tags":{},"packages":[{"name":"wireshark","source":"https://ubuntu.com/security/cve?package=wireshark","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wireshark","debian":"https://tracker.debian.org/pkg/wireshark","statuses":[{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"3.2.3-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"3.2.5-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-6262-1"],"notices":[{"id":"USN-6262-1","title":"Wireshark vulnerabilities","summary":"Several security issues were fixed in Wireshark.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-07-31T08:24:50.665134","description":"It was discovered that Wireshark did not properly handle certain\nNFS packages when certain configuration options were enabled.\nAn attacker could possibly use this issue to cause\nWireshark to crash, resulting in a denial of service. (CVE-2020-13164)\n\nIt was discovered that Wireshark did not properly handle certain GVCP\npackages. An attacker could possibly use this issue to cause\nWireshark to crash, resulting in a denial of service. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2020-15466)\n\nIt was discovered that Wireshark did not properly handle certain\nKafka packages. An attacker could possibly use this issue to cause\nWireshark to crash, resulting in a denial of service. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2020-17498)\n\nIt was discovered that Wireshark did not properly handle certain TCP\npackages containing an invalid 0xFFFF checksum. An attacker could\npossibly use this issue to cause Wireshark to crash, resulting in\na denial of service. (CVE-2020-25862)\n\nIt was discovered that Wireshark did not properly handle certain\nMIME packages containing invalid parts. An attacker could\npossibly use this issue to cause Wireshark to crash, resulting in\na denial of service. (CVE-2020-25863)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"wireshark","version":"2.6.10-1~ubuntu16.04.0+esm1","description":"network traffic analyzer - meta-package","is_source":true},{"name":"libwsutil-dev","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-dev","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"tshark","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-dev","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-qt","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap-dev","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-gtk","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwscodecs2","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-doc","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-common","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap8","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-data","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark11","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwsutil9","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark","version":"2.6.10-1~ubuntu16.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"wireshark","version":"3.2.3-1ubuntu0.1~esm1","description":"network traffic analyzer - meta-package","is_source":true},{"name":"libwsutil-dev","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-dev","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"tshark","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-dev","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-qt","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap-dev","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwsutil11","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-doc","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap10","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-common","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-gtk","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-data","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark13","version":"3.2.3-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"wireshark","version":"2.6.10-1~ubuntu18.04.0+esm1","description":"network traffic analyzer - meta-package","is_source":true},{"name":"libwsutil-dev","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-dev","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"tshark","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-dev","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-qt","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap-dev","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-gtk","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwscodecs2","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-doc","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark-common","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwiretap8","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark-data","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwireshark11","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"libwsutil9","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"},{"name":"wireshark","version":"2.6.10-1~ubuntu18.04.0+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"wireshark","version":"2.6.10-1~ubuntu14.04.0~esm2","description":"network traffic analyzer - meta-package","is_source":true},{"name":"libwsutil-dev","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-dev","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"tshark","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwireshark-dev","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-qt","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwiretap-dev","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-gtk","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwscodecs2","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-doc","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark-common","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwiretap8","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwireshark-data","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwireshark11","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"libwsutil9","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"},{"name":"wireshark","version":"2.6.10-1~ubuntu14.04.0~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/wireshark","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2020-13164","CVE-2020-17498","CVE-2020-15466","CVE-2020-25863","CVE-2020-25862"]}]},{"id":"CVE-2020-15530","published":"2020-07-05T01:15:00","updated_at":"2025-07-17T16:43:40.063173+00:00","description":"\nAn issue was discovered in Valve Steam Client 2.10.91.91. The installer\nallows local users to gain NT AUTHORITY\\SYSTEM privileges because some\nparts of %PROGRAMFILES(X86)%\\Steam and/or %COMMONPROGRAMFILES(X86)%\\Steam\nhave weak permissions during a critical time window. An attacker can make\nthis time window arbitrarily long by using opportunistic locks.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"windows-specific issue"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://daniels-it-blog.blogspot.com/2020/07/steam-arbitrary-code-execution-part-2.html","https://www.cve.org/CVERecord?id=CVE-2020-15530"],"bugs":[""],"patches":{"steam":[]},"tags":{},"packages":[{"name":"steam","source":"https://ubuntu.com/security/cve?package=steam","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=steam","debian":"https://tracker.debian.org/pkg/steam","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Steam on Windows","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-15523","published":"2020-07-04T23:15:00","updated_at":"2025-07-17T16:43:40.063173+00:00","description":"\nIn Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and\n3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in\ncases where CPython is embedded in a native application. This occurs\nbecause python3X.dll may use an invalid search path for python3.dll loading\n(after Py_SetPath has been used). NOTE: this issue CANNOT occur when using\npython.exe from a standard (non-embedded) Python installation on Windows.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"windows-specific issue, doesn't affect Ubuntu"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.python.org/issue29778","https://github.com/python/cpython/pull/21297","https://www.cve.org/CVERecord?id=CVE-2020-15523"],"bugs":[""],"patches":{"python3.8":[],"python2.7":[]},"tags":{},"packages":[{"name":"python2.7","source":"https://ubuntu.com/security/cve?package=python2.7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python2.7","debian":"https://tracker.debian.org/pkg/python2.7","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Python on Windows","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"python3.8","source":"https://ubuntu.com/security/cve?package=python3.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python3.8","debian":"https://tracker.debian.org/pkg/python3.8","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Python on Windows","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-15469","published":"2020-07-02T20:15:00","updated_at":"2026-06-09T18:40:16.717891+00:00","description":"\nIn QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback\nmethods, leading to a NULL pointer dereference.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"impact is limited, a privileged guest user can only use this\nissue to perform a denial of service to their own instance"}],"codename":null,"priority":"low","cvss3":2.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":2.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2020/07/02/1","https://lists.gnu.org/archive/html/qemu-devel/2020-06/msg09961.html (v3)","https://lists.gnu.org/archive/html/qemu-devel/2020-08/msg02003.html (v4)","https://ubuntu.com/security/notices/USN-5010-1","https://www.cve.org/CVERecord?id=CVE-2020-15469","https://ubuntu.com/security/notices/USN-8412-1"],"bugs":[""],"patches":{"qemu-kvm":[],"qemu":["upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=520f26fc6d17b71a43eaf620e834b3bdf316f3d3","upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=4f2a5202a05fc1612954804a2482f07bff105ea2","upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=24202d2b561c3b4c48bd28383c8c34b4ac66c2bf","upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=f867cebaedbc9c43189f102e4cdfdff05e88df7f","upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=b5bf601f364e1a14ca4c3276f88dfec024acf613","upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=921604e175b8ec06c39503310e7b3ec1e3eafe9e","upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=2c9fb3b784000c1df32231e1c2464bb2e3fc4620","upstream: https://git.qemu.org/?p=qemu.git;a=commit;h=735754aaa15a6ed46db51fd731e88331c446ea54"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1:5.0-5ubuntu9.9","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"released","description":"1:5.2+dfsg-9ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:2.11+dfsg-1ubuntu7.37","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:4.2-3ubuntu6.17","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"lunar","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"mantic","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"oracular","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.47+esm6","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"plucky","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"1:6.0+dfsg-1~ubuntu3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.51+esm4","component":null,"pocket":"esm-infra-legacy"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5010-1","USN-8412-1"],"notices":[{"id":"USN-5010-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2021-07-15T17:53:50.986746","description":"Lei Sun discovered that QEMU incorrectly handled certain MMIO operations.\nAn attacker inside the guest could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2020-15469)\n\nWenxiang Qian discovered that QEMU incorrectly handled certain ATAPI\ncommands. An attacker inside the guest could possibly use this issue to\ncause QEMU to crash, resulting in a denial of service. This issue only\naffected Ubuntu 21.04. (CVE-2020-29443)\n\nCheolwoo Myung discovered that QEMU incorrectly handled SCSI device\nemulation. An attacker inside the guest could possibly use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2020-35504,\nCVE-2020-35505, CVE-2021-3392)\n\nAlex Xu discovered that QEMU incorrectly handled the virtio-fs shared file\nsystem daemon. An attacker inside the guest could possibly use this issue\nto read and write to host devices. This issue only affected Ubuntu 20.10.\n(CVE-2020-35517)\n\nIt was discovered that QEMU incorrectly handled ARM Generic Interrupt\nController emulation. An attacker inside the guest could possibly use this\nissue to cause QEMU to crash, resulting in a denial of service. This issue\nonly affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10.\n(CVE-2021-20221)\n\nAlexander Bulekov, Cheolwoo Myung, Sergej Schumilo, Cornelius Aschermann,\nand Simon Werner discovered that QEMU incorrectly handled e1000 device\nemulation. An attacker inside the guest could possibly use this issue to\ncause QEMU to hang, resulting in a denial of service. This issue only\naffected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10.\n(CVE-2021-20257)\n\nIt was discovered that QEMU incorrectly handled SDHCI controller emulation.\nAn attacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service, or possibly execute arbitrary code. In\nthe default installation, when QEMU is used in combination with libvirt,\nattackers would be isolated by the libvirt AppArmor profile.\n(CVE-2021-3409)\n\nIt was discovered that QEMU incorrectly handled certain NIC emulation\ndevices. An attacker inside the guest could possibly use this issue to\ncause QEMU to hang or crash, resulting in a denial of service. This issue\nonly affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 20.10.\n(CVE-2021-3416)\n\nRemy Noel discovered that QEMU incorrectly handled the USB redirector\ndevice. An attacker inside the guest could possibly use this issue to\ncause QEMU to consume resources, resulting in a denial of service.\n(CVE-2021-3527)\n\nIt was discovered that QEMU incorrectly handled the virtio vhost-user GPU\ndevice. An attacker inside the guest could possibly use this issue to cause\nQEMU to consume resources, leading to a denial of service. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-3544)\n\nIt was discovered that QEMU incorrectly handled the virtio vhost-user GPU\ndevice. An attacker inside the guest could possibly use this issue to\nobtain sensitive host information. This issue only affected Ubuntu 20.04\nLTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-3545)\n\nIt was discovered that QEMU incorrectly handled the virtio vhost-user GPU\ndevice. An attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. In the default installation, when QEMU is used in combination with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile. This\nissue only affected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04.\n(CVE-2021-3546)\n\nIt was discovered that QEMU incorrectly handled the PVRDMA device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service, or possibly execute arbitrary code. In\nthe default installation, when QEMU is used in combination with libvirt,\nattackers would be isolated by the libvirt AppArmor profile. This issue\nonly affected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04.\n(CVE-2021-3582, CVE-2021-3607, CVE-2021-3608)\n\nIt was discovered that QEMU SLiRP networking incorrectly handled certain\nudp packets. An attacker inside a guest could possibly use this issue to\nleak sensitive information from the host. (CVE-2021-3592, CVE-2021-3593,\nCVE-2021-3594, CVE-2021-3595)\n","is_hidden":false,"release_packages":{"groovy":[{"name":"qemu","version":"1:5.0-5ubuntu9.9","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system-x86-microvm","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-common","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-user-static","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-misc","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-block-extra","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-s390x","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-kvm","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-user","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-guest-agent","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-utils","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-data","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-x86","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-sparc","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-gui","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-arm","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-ppc","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-mips","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"},{"name":"qemu-system-x86-xen","version":"1:5.0-5ubuntu9.9","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.0-5ubuntu9.9","pocket":"security"}],"hirsute":[{"name":"qemu","version":"1:5.2+dfsg-9ubuntu3.1","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system-x86-microvm","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-common","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-user-static","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-misc","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-block-extra","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-s390x","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-user","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-guest-agent","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-utils","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-data","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-x86","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-sparc","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-gui","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-arm","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-ppc","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-mips","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"},{"name":"qemu-system-x86-xen","version":"1:5.2+dfsg-9ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:5.2+dfsg-9ubuntu3.1","pocket":"security"}],"focal":[{"name":"qemu","version":"1:4.2-3ubuntu6.17","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system-x86-microvm","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-common","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-user-static","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-misc","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-block-extra","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-s390x","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-kvm","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-user","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-guest-agent","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-utils","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-data","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-x86","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-sparc","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-gui","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-arm","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-ppc","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-mips","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"},{"name":"qemu-system-x86-xen","version":"1:4.2-3ubuntu6.17","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:4.2-3ubuntu6.17","pocket":"security"}],"bionic":[{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.37","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system-common","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-user-static","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-kvm","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-user","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-system","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-utils","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.11+dfsg-1ubuntu7.37","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.11+dfsg-1ubuntu7.37","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3594","CVE-2021-3546","CVE-2021-3545","CVE-2020-35504","CVE-2020-15469","CVE-2021-3593","CVE-2021-3416","CVE-2021-3582","CVE-2021-3544","CVE-2021-20257","CVE-2020-29443","CVE-2021-3527","CVE-2021-3607","CVE-2021-3595","CVE-2020-35505","CVE-2021-3392","CVE-2021-3409","CVE-2021-20221","CVE-2021-3608","CVE-2020-35517","CVE-2021-3592"]},{"id":"USN-8412-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.","references":[],"published":"2026-06-09T16:22:49.156514","description":"Felipe Franciosi, Raphael Norwitz, and Peter Turschmid discovered that the\niSCSI block driver in QEMU incorrectly handled certain responses from an\niSCSI server. A remote attacker could possibly use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-1711)\n\nIt was discovered that the iSCSI block driver in QEMU incorrectly handled\ncertain memory operations, leading to a heap-based buffer over-read. An\nattacker could possibly use this issue to expose sensitive information from\nthe host. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-11947)\n\nZiming Zhang discovered that the SM501 display driver in QEMU contained an\ninteger overflow. A local attacker could possibly use this issue to cause\nQEMU to crash, resulting in a denial of service. This issue only affected\nUbuntu 14.04 LTS. (CVE-2020-12829)\n\nGaoning Pan and Xingwei Li discovered that the USB xHCI controller\nimplementation in QEMU contained an infinite loop. An attacker inside the\nguest could possibly use this issue to cause QEMU to hang, resulting in a\ndenial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04\nLTS, and Ubuntu 18.04 LTS. (CVE-2020-14394)\n\nLei Sun discovered that QEMU incorrectly handled certain MemoryRegionOps\nobjects, leading to a NULL pointer dereference. An attacker inside the\nguest could possibly use this issue to cause QEMU to crash, resulting in a\ndenial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2020-15469)\n\nAlexander Bulekov discovered that the e1000e network device implementation\nin QEMU contained a use-after-free. An attacker inside the guest could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-15859)\n\nZiming Zhang discovered that the XGMAC Ethernet controller in QEMU\ncontained a buffer overflow. An attacker inside the guest could possibly\nuse this issue to cause QEMU to crash, resulting in a denial of service, or\npossibly execute arbitrary code. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2020-15863)\n\nAlexander Bulekov discovered that the SDHCI device emulation in QEMU\ncontained a heap-based buffer overflow. An attacker inside the guest could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. This issue only affected\nUbuntu 14.04 LTS. (CVE-2020-17380)\n\nSergej Schumilo, Cornelius Aschermann, and Simon Wörner discovered that the\nUSB xHCI controller implementation in QEMU did not check a return value,\nleading to a use-after-free. An attacker inside the guest could possibly\nuse this issue to cause QEMU to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 14.04 LTS. (CVE-2020-25084)\n\nGaoning Pan, Yongkang Jia, and Yi Ren discovered that the USB OHCI\ncontroller implementation in QEMU contained a stack-based buffer over-read.\nAn attacker inside the guest could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS. (CVE-2020-25624)\n\nIt was discovered that the USB OHCI controller implementation in QEMU\ncontained an infinite loop. An attacker inside the guest could possibly use\nthis issue to cause QEMU to consume resources, resulting in a denial of\nservice. This issue only affected Ubuntu 14.04 LTS. (CVE-2020-25625)\n\nCheolwoo Myung discovered that the USB EHCI emulation in QEMU did not\nhandle DMA memory map failures, leading to a reachable assertion. An\nattacker inside the guest could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS. (CVE-2020-25723)\n\nGaoning Pan discovered that the network device emulation in QEMU could be\nmade to trigger an assertion failure when processing packets that lacked a\nvalid layer 3 protocol. An attacker inside the guest could possibly use\nthis issue to cause QEMU to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2020-27617)\n\nWenxiang Qian discovered that the ATAPI emulation in QEMU did not properly\nvalidate a buffer index, leading to an out-of-bounds read. An attacker\ninside the guest could possibly use this issue to expose sensitive\ninformation or cause QEMU to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS. (CVE-2020-29443)\n\nCheolwoo Myung discovered that the ESP SCSI emulation in QEMU contained a\nNULL pointer dereference. An attacker inside the guest could possibly use\nthis issue to cause QEMU to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2020-35504)\n\nCheolwoo Myung discovered that the am53c974 SCSI host bus adapter emulation\nin QEMU contained a NULL pointer dereference. An attacker inside the guest\ncould possibly use this issue to cause QEMU to crash, resulting in a denial\nof service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2020-35505)\n\nIt was discovered that the SDHCI controller emulation in QEMU contained\nout-of-bounds read and write issues. An attacker inside the guest could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice, or possibly execute arbitrary code. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3409)\n\nIt was discovered that several network device emulations in QEMU contained\nan infinite loop when operating in loopback mode. An attacker inside the\nguest could possibly use this issue to cause QEMU to crash, resulting in a\ndenial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2021-3416)\n\nAlexander Bulekov discovered that the floppy disk emulation in QEMU\ncontained a heap-based buffer overflow. An attacker inside the guest could\npossibly use this issue to expose sensitive information or cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3507)\n\nRemy Noel discovered that the USB redirector device emulation in QEMU\nperformed an unbounded stack allocation when combining USB packets. An\nattacker inside the guest could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-3527)\n\nIt was discovered that the QXL display device emulation in QEMU contained\nan integer overflow, leading to a heap-based buffer overflow. An attacker\ninside the guest could possibly use this issue to cause QEMU to crash,\nresulting in a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-4206)\n\nIt was discovered that the QXL display device emulation in QEMU performed a\ndouble fetch of guest-controlled values, leading to a heap-based buffer\noverflow. An attacker inside the guest could possibly use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04\nLTS. (CVE-2021-4207)\n\nIt was discovered that the 9pfs server implementation in QEMU contained a\nrace condition, leading to a use-after-free. A malicious 9p client could\npossibly use this issue to escalate privileges. This issue only affected\nUbuntu 14.04 LTS. (CVE-2021-20181)\n\nGaoning Pan discovered that the floppy disk emulation in QEMU contained a\nNULL pointer dereference. An attacker inside the guest could possibly use\nthis issue to cause QEMU to crash, resulting in a denial of service. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2021-20196)\n\nGaoning Pan discovered that the vmxnet3 network device emulation in QEMU\ncontained an integer overflow. An attacker inside the guest could possibly\nuse this issue to cause QEMU to crash, resulting in a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2021-20203)\n\nIt was discovered that the ARM Generic Interrupt Controller emulation in\nQEMU contained an out-of-bounds heap access. An attacker inside the guest\ncould possibly use this issue to cause QEMU to crash, resulting in a denial\nof service. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2021-20221)\n\nAlexander Bulekov, Cheolwoo Myung, Sergej Schumilo, Cornelius Aschermann,\nand Simon Wörner discovered that the e1000 network device emulation in QEMU\ncontained an infinite loop. An attacker inside the guest could possibly use\nthis issue to cause QEMU to consume resources, resulting in a denial of\nservice. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2021-20257)\n\nIt was discovered that the 9p passthrough file system implementation in\nQEMU did not prevent opening special files on the host. A malicious guest\ncould possibly use this issue to escape the exported 9p tree. This issue\nonly affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS.\n(CVE-2023-2861)\n\nIt was discovered that the virtio crypto device emulation in QEMU did not\nproperly validate certain buffer lengths, leading to a heap buffer\noverflow. An attacker inside the guest could possibly use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-3180)\n\nIt was discovered that the built-in VNC server in QEMU contained a NULL\npointer dereference when cleaning up a connection that failed during the\nhandshake. A remote attacker could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n18.04 LTS. (CVE-2023-3354)\n\nIt was discovered that QEMU could incorrectly direct a guest I/O operation\nto disk offset 0 instead of the intended offset. An attacker inside the\nguest could possibly use this issue to read or overwrite sensitive data,\npotentially gaining control of the host. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2023-5088)\n\nIt was discovered that several virtio device emulations in QEMU did not\nproperly guard against DMA reentrancy, leading to a double free. An\nattacker inside the guest could possibly use this issue to cause QEMU to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2024-3446)\n\nIt was discovered that the SDHCI device emulation in QEMU contained a heap-\nbased buffer overflow. An attacker inside the guest could possibly use this\nissue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2024-3447)\n\nIt was discovered that the QEMU disk image utility (qemu-img) did not\nproperly handle certain crafted image files. An attacker could possibly use\nthis issue to cause qemu-img to consume excessive resources or access an\nunintended external file, resulting in a denial of service. This issue only\naffected Ubuntu 20.04 LTS. (CVE-2024-4467)\n\nCyrille Chatras discovered that the LSI53C895A SCSI Host Bus Adapter\nemulation in QEMU contained a use-after-free. An attacker inside the guest\ncould possibly use this issue to cause QEMU to crash, resulting in a denial\nof service, or possibly execute arbitrary code. (CVE-2024-6519)\n\nIt was discovered that the NBD server in QEMU contained an improper\nsynchronization issue during socket closure. A remote attacker could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice. (CVE-2024-7409)\n\nIt was discovered that the USB emulation in QEMU contained a reachable\nassertion. An attacker inside the guest could possibly use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2024-8354)\n\nIt was discovered that QEMU incorrectly handled resources during the VNC\nWebSocket handshake, leading to a use-after-free. A remote attacker could\npossibly use this issue to cause QEMU to crash, resulting in a denial of\nservice. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n(CVE-2025-11234)\n\nIt was discovered that QEMU could be made to read out of bounds when\nreading VMDK images. An attacker could possibly use this issue to expose\nsensitive information or cause QEMU to crash, resulting in a denial of\nservice. (CVE-2026-2243)","is_hidden":false,"release_packages":{"bionic":[{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.42+esm5","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-block-extra","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-guest-agent","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-kvm","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-arm","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-common","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-mips","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-misc","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-ppc","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-s390x","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-sparc","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-x86","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user-binfmt","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user-static","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-utils","version":"1:2.11+dfsg-1ubuntu7.42+esm5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"qemu","version":"1:4.2-3ubuntu6.30+esm1","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-block-extra","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-guest-agent","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-kvm","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-arm","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-common","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-data","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-gui","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-mips","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-misc","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-ppc","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-s390x","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-sparc","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-x86","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-x86-microvm","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-system-x86-xen","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user-binfmt","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-user-static","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"},{"name":"qemu-utils","version":"1:4.2-3ubuntu6.30+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra"}],"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.47+esm6","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.47+esm6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.51+esm4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.51+esm4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2021-3416","CVE-2020-15469","CVE-2020-1711","CVE-2021-3409","CVE-2024-3447","CVE-2023-5088","CVE-2020-29443","CVE-2020-35504","CVE-2020-35505","CVE-2020-25723","CVE-2021-4206","CVE-2024-3446","CVE-2024-7409","CVE-2024-8354","CVE-2020-11947","CVE-2026-2243","CVE-2023-3180","CVE-2021-4207","CVE-2021-20221","CVE-2020-27617","CVE-2023-3354","CVE-2020-14394","CVE-2020-15863","CVE-2020-25084","CVE-2024-6519","CVE-2024-4467","CVE-2021-3527","CVE-2020-25625","CVE-2021-20257","CVE-2020-25624","CVE-2021-3507","CVE-2025-11234","CVE-2021-20203","CVE-2020-17380","CVE-2023-2861","CVE-2021-20196","CVE-2021-20181","CVE-2020-12829","CVE-2020-15859"]}]},{"id":"CVE-2020-8185","published":"2020-07-02T19:15:00","updated_at":"2025-07-11T07:45:54.037247+00:00","description":"\nA denial of service vulnerability exists in Rails <6.0.3.2 that allowed an\nuntrusted user to run any pending migrations on a Rails app running in\nproduction.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://groups.google.com/g/rubyonrails-security/c/pAe9EV8gbM0","https://www.cve.org/CVERecord?id=CVE-2020-8185"],"bugs":[""],"patches":{"rails":[],"ruby-rails-3.2":[],"ruby-actionpack-3.2":[],"ruby-activesupport-3.2":[],"ruby-activerecord-3.2":[],"ruby-activemodel-3.2":[],"rails-4.0":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"debian: Introduced in rails 6.x","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"rails-4.0","source":"https://ubuntu.com/security/cve?package=rails-4.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rails-4.0","debian":"https://tracker.debian.org/pkg/rails-4.0","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-actionpack-3.2","source":"https://ubuntu.com/security/cve?package=ruby-actionpack-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-actionpack-3.2","debian":"https://tracker.debian.org/pkg/ruby-actionpack-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activemodel-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activemodel-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-activemodel-3.2","debian":"https://tracker.debian.org/pkg/ruby-activemodel-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activerecord-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activerecord-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-activerecord-3.2","debian":"https://tracker.debian.org/pkg/ruby-activerecord-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activesupport-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activesupport-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-activesupport-3.2","debian":"https://tracker.debian.org/pkg/ruby-activesupport-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-rails-3.2","source":"https://ubuntu.com/security/cve?package=ruby-rails-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-rails-3.2","debian":"https://tracker.debian.org/pkg/ruby-rails-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-8166","published":"2020-07-02T19:15:00","updated_at":"2025-08-26T12:26:43.795221+00:00","description":"\nA CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that\nmakes it possible for an attacker to, given a global CSRF token such as the\none present in the authenticity_token meta tag, forge a per-form CSRF\ntoken.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://weblog.rubyonrails.org/2020/5/18/Rails-5-2-4-3-and-6-0-3-1-have-been-released","https://github.com/rails/rails/commit/d124f19287f4892c72ca54da728a781591c6fca1","https://www.cve.org/CVERecord?id=CVE-2020-8166"],"bugs":[""],"patches":{"rails":[],"ruby-rails-3.2":[],"ruby-actionpack-3.2":[],"ruby-activesupport-3.2":[],"ruby-activerecord-3.2":[],"ruby-activemodel-3.2":[],"rails-4.0":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2:5.2.4.3+dfsg-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"rails-4.0","source":"https://ubuntu.com/security/cve?package=rails-4.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rails-4.0","debian":"https://tracker.debian.org/pkg/rails-4.0","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-actionpack-3.2","source":"https://ubuntu.com/security/cve?package=ruby-actionpack-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-actionpack-3.2","debian":"https://tracker.debian.org/pkg/ruby-actionpack-3.2","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activemodel-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activemodel-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-activemodel-3.2","debian":"https://tracker.debian.org/pkg/ruby-activemodel-3.2","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activerecord-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activerecord-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-activerecord-3.2","debian":"https://tracker.debian.org/pkg/ruby-activerecord-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activesupport-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activesupport-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-activesupport-3.2","debian":"https://tracker.debian.org/pkg/ruby-activesupport-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-rails-3.2","source":"https://ubuntu.com/security/cve?package=ruby-rails-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-rails-3.2","debian":"https://tracker.debian.org/pkg/ruby-rails-3.2","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-8163","published":"2020-07-02T19:15:00","updated_at":"2025-07-11T07:45:54.037247+00:00","description":"\nThe is a code injection vulnerability in versions of Rails prior to 5.0.1\nthat wouldallow an attacker who controlled the `locals` argument of a\n`render` call to perform a RCE.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"In Oneiric-Saucy, rails package is just for transition;\nThe rails package contains actual code from vivid onward"}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://weblog.rubyonrails.org/2020/5/16/rails-4-2-11-3-has-been-released/","https://github.com/rails/rails/commit/4c46a15e0a7815ca9e4cd7c7fda042eb8c1b7724 (4.2.11.2)","https://github.com/rails/rails/commit/1f3db0ad793441a0c00e85d56228fc80aafbe6c1 (4.2.11.3)","https://www.cve.org/CVERecord?id=CVE-2020-8163"],"bugs":[""],"patches":{"rails":[],"ruby-rails-3.2":[],"ruby-actionpack-3.2":[],"ruby-activesupport-3.2":[],"ruby-activerecord-3.2":[],"ruby-activemodel-3.2":[],"rails-4.0":[]},"tags":{},"packages":[{"name":"rails","source":"https://ubuntu.com/security/cve?package=rails","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rails","debian":"https://tracker.debian.org/pkg/rails","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"rails-4.0","source":"https://ubuntu.com/security/cve?package=rails-4.0","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rails-4.0","debian":"https://tracker.debian.org/pkg/rails-4.0","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-actionpack-3.2","source":"https://ubuntu.com/security/cve?package=ruby-actionpack-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-actionpack-3.2","debian":"https://tracker.debian.org/pkg/ruby-actionpack-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activemodel-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activemodel-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-activemodel-3.2","debian":"https://tracker.debian.org/pkg/ruby-activemodel-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activerecord-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activerecord-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-activerecord-3.2","debian":"https://tracker.debian.org/pkg/ruby-activerecord-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-activesupport-3.2","source":"https://ubuntu.com/security/cve?package=ruby-activesupport-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-activesupport-3.2","debian":"https://tracker.debian.org/pkg/ruby-activesupport-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"ruby-rails-3.2","source":"https://ubuntu.com/security/cve?package=ruby-rails-3.2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-rails-3.2","debian":"https://tracker.debian.org/pkg/ruby-rails-3.2","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2020-8161","published":"2020-07-02T19:15:00","updated_at":"2025-08-25T23:29:17.102631+00:00","description":"\nA directory traversal vulnerability exists in rack < 2.2.0 that allows an\nattacker perform directory traversal vulnerability in the Rack::Directory\napp that is bundled with Rack which could result in information disclosure.","ubuntu_description":"\nIt was discovered that Rack incorrectly handled certain paths. An attacker\ncould possibly use this issue to obtain sensitive information.","notes":[],"codename":null,"priority":"low","cvss3":8.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":8.6,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://groups.google.com/forum/#!msg/rubyonrails-security/IOO1vNZTzPA/Ylzi1UYLAAAJ","https://github.com/rack/rack/commit/dddb7ad18ed79ca6ab06ccc417a169fde451246e","https://ubuntu.com/security/notices/USN-4561-1","https://ubuntu.com/security/notices/USN-4561-2","https://www.cve.org/CVERecord?id=CVE-2020-8161"],"bugs":[""],"patches":{"ruby-rack":["upstream: https://github.com/rack/rack/commit/dddb7ad18ed79ca6ab06ccc417a169fde451246e","upstream: https://github.com/rack/rack/commit/e7ba1b0557d3ad97af1ef113bbeb5f27417983fa"]},"tags":{},"packages":[{"name":"ruby-rack","source":"https://ubuntu.com/security/cve?package=ruby-rack","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-rack","debian":"https://tracker.debian.org/pkg/ruby-rack","statuses":[{"release_codename":"bionic","status":"released","description":"1.6.4-4ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.1.1-5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.1.1-5","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.1.1-5","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.1.1-5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"2.0.7-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.5.2-3+deb8u3","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"1.5.2-3+deb8u3, 1.6.4-4+deb9u2, 2.1.1-5, 2.1.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.6.4-3ubuntu0.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-4561-1","USN-4561-2"],"notices":[{"id":"USN-4561-1","title":"Rack vulnerabilities","summary":"Rack could be made to expose sensitive information over the network.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-09-30T19:08:21.854158","description":"It was discovered that Rack incorrectly handled certain paths. An attacker\ncould possibly use this issue to obtain sensitive information.\n(CVE-2020-8161)\n\nIt was discovered that Rack incorrectly validated cookies. An attacker\ncould possibly use this issue to forge a secure cookie. (CVE-2020-8184)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-4ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/1.6.4-4ubuntu0.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-8161","CVE-2020-8184"]},{"id":"USN-4561-2","title":"Rack vulnerabilities","summary":"Rack could be made to expose sensitive information over the network.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-04-06T11:13:44.383235","description":"USN-4561-1 fixed vulnerabilities in Rack. This update provides the\ncorresponding update for Ubuntu 16.04 LTS, Ubuntu 20.04 LTS and Ubuntu 20.10.\n\nOriginal advisory details:\n\n It was discovered that Rack incorrectly handled certain paths. An attacker\n could possibly use this issue to obtain sensitive information. This issue\n only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS.\n (CVE-2020-8161)\n\n It was discovered that Rack incorrectly validated cookies. An attacker\n could possibly use this issue to forge a secure cookie. (CVE-2020-8184)\n","is_hidden":false,"release_packages":{"focal":[{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.0.7-2ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.0.7-2ubuntu0.1","pocket":"security"}],"groovy":[{"name":"ruby-rack","version":"2.1.1-5ubuntu0.1","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"2.1.1-5ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/2.1.1-5ubuntu0.1","pocket":"security"}],"xenial":[{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2","description":"modular Ruby webserver interface","is_source":true},{"name":"ruby-rack","version":"1.6.4-3ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ruby-rack","version_link":"https://launchpad.net/ubuntu/+source/ruby-rack/1.6.4-3ubuntu0.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-8161","CVE-2020-8184"]}]},{"id":"CVE-2020-15503","published":"2020-07-02T14:15:00","updated_at":"2025-07-11T07:43:40.768663+00:00","description":"\nLibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects\ndecoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and\nutils/thumb_utils.cpp. For example,\nmalloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without\nvalidating T.tlength.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/LibRaw/LibRaw/compare/0.20-Beta3...0.20-RC1","https://www.libraw.org/news/libraw-0-20-rc1","https://ubuntu.com/security/notices/USN-5715-1","https://www.cve.org/CVERecord?id=CVE-2020-15503"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1853477","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=964747"],"patches":{"libraw":["upstream: https://github.com/LibRaw/LibRaw/commit/20ad21c0d87ca80217aee47533d91e633ce1864d"],"ufraw":[],"darktable":[],"exactimage":[],"dcraw":[],"rawtherapee":[],"xbmc":[],"kodi":[]},"tags":{},"packages":[{"name":"ufraw","source":"https://ubuntu.com/security/cve?package=ufraw","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ufraw","debian":"https://tracker.debian.org/pkg/ufraw","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"darktable","source":"https://ubuntu.com/security/cve?package=darktable","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=darktable","debian":"https://tracker.debian.org/pkg/darktable","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"exactimage","source":"https://ubuntu.com/security/cve?package=exactimage","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exactimage","debian":"https://tracker.debian.org/pkg/exactimage","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"dcraw","source":"https://ubuntu.com/security/cve?package=dcraw","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=dcraw","debian":"https://tracker.debian.org/pkg/dcraw","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]},{"name":"rawtherapee","source":"https://ubuntu.com/security/cve?package=rawtherapee","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=rawtherapee","debian":"https://tracker.debian.org/pkg/rawtherapee","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"kodi","source":"https://ubuntu.com/security/cve?package=kodi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=kodi","debian":"https://tracker.debian.org/pkg/kodi","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libraw","source":"https://ubuntu.com/security/cve?package=libraw","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libraw","debian":"https://tracker.debian.org/pkg/libraw","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.18.8-1ubuntu0.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"0.19.5-1ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.20.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.20.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.20.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.20.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.20.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.20.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.20.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.20.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.20.2-2ubuntu2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"xbmc","source":"https://ubuntu.com/security/cve?package=xbmc","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=xbmc","debian":"https://tracker.debian.org/pkg/xbmc","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-5715-1"],"notices":[{"id":"USN-5715-1","title":"LibRaw vulnerabilities","summary":"Several security issues were fixed in LibRaw.\n","instructions":"After a standard system update you need to restart your session to make all\nthe necessary changes.\n","references":[],"published":"2022-11-07T16:57:39.313200","description":"It was discovered that LibRaw incorrectly handled photo files. If a user or\nautomated system were tricked into processing a specially crafted photo\nfile, a remote attacker could cause applications linked against LibRaw to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"libraw","version":"0.18.8-1ubuntu0.4","description":"raw image decoder library","is_source":true},{"name":"libraw-doc","version":"0.18.8-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.18.8-1ubuntu0.4","pocket":"security"},{"name":"libraw-bin","version":"0.18.8-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.18.8-1ubuntu0.4","pocket":"security"},{"name":"libraw16","version":"0.18.8-1ubuntu0.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.18.8-1ubuntu0.4","pocket":"security"},{"name":"libraw-dev","version":"0.18.8-1ubuntu0.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.18.8-1ubuntu0.4","pocket":"security"}],"focal":[{"name":"libraw","version":"0.19.5-1ubuntu1.1","description":"raw image decoder library","is_source":true},{"name":"libraw-doc","version":"0.19.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.19.5-1ubuntu1.1","pocket":"security"},{"name":"libraw-bin","version":"0.19.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.19.5-1ubuntu1.1","pocket":"security"},{"name":"libraw19","version":"0.19.5-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.19.5-1ubuntu1.1","pocket":"security"},{"name":"libraw-dev","version":"0.19.5-1ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libraw","version_link":"https://launchpad.net/ubuntu/+source/libraw/0.19.5-1ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2020-15503","CVE-2020-35531","CVE-2020-35533","CVE-2020-35532","CVE-2020-35530"]}]}],"offset":45140,"limit":20,"total_results":79316}