{"cves":[{"id":"CVE-2018-17235","published":"2018-09-20T06:29:00","updated_at":"2025-08-26T12:05:24.036876+00:00","description":"\nThe function mp4v2::impl::MP4Track::FinishSdtp() in mp4track.cpp in\nlibmp4v2 2.1.0 mishandles compatibleBrand while processing a crafted mp4\nfile, which leads to a heap-based buffer over-read, causing denial of\nservice.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://bugzilla.redhat.com/show_bug.cgi?id=1629451","https://www.cve.org/CVERecord?id=CVE-2018-17235"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=909278"],"patches":{"mp4v2":[]},"tags":{},"packages":[{"name":"mp4v2","source":"https://ubuntu.com/security/cve?package=mp4v2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mp4v2","debian":"https://tracker.debian.org/pkg/mp4v2","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"pending","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-17234","published":"2018-09-20T06:29:00","updated_at":"2025-08-25T22:49:45.787639+00:00","description":"\nMemory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the\nHDF HDF5 through 1.10.3 library allows attackers to cause a denial of\nservice (memory consumption) via a crafted HDF5 file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/SegfaultMasters/covering360/tree/master/HDF5/vuln3#memory-leak---h5o__chunk_deserialize_memory_leak","https://ubuntu.com/security/notices/USN-5272-1","https://www.cve.org/CVERecord?id=CVE-2018-17234"],"bugs":[""],"patches":{"hdf5":["upstream: https://bitbucket.hdfgroup.org/projects/HDFFV/repos/hdf5/commits/f4138013dbc6851e968ea3d37b32776538ef306b"]},"tags":{},"packages":[{"name":"hdf5","source":"https://ubuntu.com/security/cve?package=hdf5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hdf5","debian":"https://tracker.debian.org/pkg/hdf5","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.10.0-patch1+docs-4ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1.10.4+repack-11ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.8.11-5ubuntu7.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"upstream","status":"released","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.8.16+docs-4ubuntu1.1+esm2","component":null,"pocket":"esm-apps"},{"release_codename":"mantic","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5272-1"],"notices":[{"id":"USN-5272-1","title":"HDF5 vulnerabilities","summary":"HDF5 could be made to crash if it opened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-07-20T14:48:32.724361","description":"It was discovered that HDF5 incorrectly handled certain inputs. An\nattacker could possibly use this issue to cause a denial of service.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"hdf5","version":"1.8.16+docs-4ubuntu1.1+esm2","description":"Hierarchical Data Format 5 (HDF5)","is_source":true},{"name":"libhdf5-doc","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-10","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-cpp-11","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-helpers","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-10","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-10","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpi-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-serial-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-tools","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"hdf5","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","description":"Hierarchical Data Format 5 (HDF5)","is_source":true},{"name":"libhdf5-doc","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-helpers","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-cpp-100","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-100","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-100","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-100","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-jni","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-java","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpi-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-serial-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-tools","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"hdf5","version":"1.10.4+repack-11ubuntu1+esm1","description":"Hierarchical Data Format 5 (HDF5)","is_source":true},{"name":"libhdf5-103","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-doc","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-helpers","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-cpp-103","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-jni","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-dev","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-103","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-dev","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-dev","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-103","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-java","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpi-dev","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-tools","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"hdf5","version":"1.8.11-5ubuntu7.1+esm2","description":"Hierarchical Data Format 5 (HDF5)","is_source":true},{"name":"libhdf5-doc","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-mpich2-7","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"hdf5-helpers","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-7","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-openmpi-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-mpich2-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-mpi-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-serial-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-openmpi-7","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"hdf5-tools","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-17233","CVE-2018-17237","CVE-2018-17234"]}]},{"id":"CVE-2018-17233","published":"2018-09-20T06:29:00","updated_at":"2025-08-25T22:49:45.787639+00:00","description":"\nA SIGFPE signal is raised in the function\nH5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through\n1.10.3 library during an attempted parse of a crafted HDF file, because of\nincorrect protection against division by zero. It could allow a remote\ndenial of service attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/SegfaultMasters/covering360/tree/master/HDF5/vuln2#divided-by-zero---h5d__create_chunk_file_map_hyper_div_zero","https://ubuntu.com/security/notices/USN-5272-1","https://www.cve.org/CVERecord?id=CVE-2018-17233"],"bugs":[""],"patches":{"hdf5":[]},"tags":{},"packages":[{"name":"hdf5","source":"https://ubuntu.com/security/cve?package=hdf5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hdf5","debian":"https://tracker.debian.org/pkg/hdf5","statuses":[{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.8.11-5ubuntu7.1+esm2","component":null,"pocket":"esm-infra"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.8.16+docs-4ubuntu1.1+esm2","component":null,"pocket":"esm-apps"},{"release_codename":"focal","status":"released","description":"1.10.4+repack-11ubuntu1+esm1","component":null,"pocket":"esm-apps"},{"release_codename":"lunar","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.10.0-patch1+docs-4ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.10.5+repack-1~exp1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5272-1"],"notices":[{"id":"USN-5272-1","title":"HDF5 vulnerabilities","summary":"HDF5 could be made to crash if it opened a specially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-07-20T14:48:32.724361","description":"It was discovered that HDF5 incorrectly handled certain inputs. An\nattacker could possibly use this issue to cause a denial of service.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"hdf5","version":"1.8.16+docs-4ubuntu1.1+esm2","description":"Hierarchical Data Format 5 (HDF5)","is_source":true},{"name":"libhdf5-doc","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-10","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-cpp-11","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-helpers","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-10","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-10","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpi-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-serial-dev","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-tools","version":"1.8.16+docs-4ubuntu1.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"}],"bionic":[{"name":"hdf5","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","description":"Hierarchical Data Format 5 (HDF5)","is_source":true},{"name":"libhdf5-doc","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-helpers","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-cpp-100","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-100","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-100","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-100","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-jni","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-java","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpi-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-serial-dev","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-tools","version":"1.10.0-patch1+docs-4ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"hdf5","version":"1.10.4+repack-11ubuntu1+esm1","description":"Hierarchical Data Format 5 (HDF5)","is_source":true},{"name":"libhdf5-103","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-doc","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-helpers","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-cpp-103","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-jni","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-dev","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-103","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-dev","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpich-dev","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-openmpi-103","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-java","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"libhdf5-mpi-dev","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"},{"name":"hdf5-tools","version":"1.10.4+repack-11ubuntu1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"hdf5","version":"1.8.11-5ubuntu7.1+esm2","description":"Hierarchical Data Format 5 (HDF5)","is_source":true},{"name":"libhdf5-doc","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-mpich2-7","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"hdf5-helpers","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-7","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-openmpi-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-mpich2-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-mpi-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-serial-dev","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"libhdf5-openmpi-7","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"},{"name":"hdf5-tools","version":"1.8.11-5ubuntu7.1+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/hdf5","version_link":null,"pocket":"esm-infra"}]},"type":"USN","cves_ids":["CVE-2018-17233","CVE-2018-17237","CVE-2018-17234"]}]},{"id":"CVE-2018-17231","published":"2018-09-19T22:29:00","updated_at":"2025-08-04T19:27:32.615798+00:00","description":"\nTelegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a\ndenial of service (assertion failure and application exit) via an \"Edit\ncolor palette\" search that triggers an \"index out of range\" condition.\nNOTE: this issue is disputed by multiple third parties because the\ndescribed attack scenario does not cross a privilege boundary","ubuntu_description":"","notes":[{"author":"ebarretto","note":"Disputed as attack scenario does not cross a privilege boundary."}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-17231"],"bugs":[""],"patches":{"telegram-desktop":[]},"tags":{},"packages":[{"name":"telegram-desktop","source":"https://ubuntu.com/security/cve?package=telegram-desktop","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=telegram-desktop","debian":"https://tracker.debian.org/pkg/telegram-desktop","statuses":[{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"disputed","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"disputed","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-17230","published":"2018-09-19T22:29:00","updated_at":"2025-08-25T22:49:45.787639+00:00","description":"\nExiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause\na denial of service (heap-based buffer overflow) via a crafted image file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"fixed by afb98cbc6e288dc8ea75f3394a347fb9b37abc55, which\nintroduced CVE-2018-17282"},{"author":"leosilva","note":"code vulnerable was introduced later in version 0.27."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-17230"],"bugs":["https://github.com/Exiv2/exiv2/issues/455"],"patches":{"exiv2":["upstream: https://github.com/Exiv2/exiv2/commit/afb98cbc6e288dc8ea75f3394a347fb9b37abc55"]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-17229","published":"2018-09-19T22:29:00","updated_at":"2025-08-25T22:49:45.787639+00:00","description":"\nExiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause\na denial of service (heap-based buffer overflow) via a crafted image file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"fixed by afb98cbc6e288dc8ea75f3394a347fb9b37abc55, which\nintroduced CVE-2018-17282"},{"author":"leosilva","note":"vulnerable code was introduced in 0.27-RC1 (later)."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-17229"],"bugs":["https://github.com/Exiv2/exiv2/issues/453"],"patches":{"exiv2":["upstream: https://github.com/Exiv2/exiv2/commit/afb98cbc6e288dc8ea75f3394a347fb9b37abc55"]},"tags":{},"packages":[{"name":"exiv2","source":"https://ubuntu.com/security/cve?package=exiv2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=exiv2","debian":"https://tracker.debian.org/pkg/exiv2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3831","published":"2018-09-19T19:29:00","updated_at":"2025-08-25T22:54:20.923035+00:00","description":"\nElasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12\nhave an information disclosure issue when secrets are configured via the\nAPI. The Elasticsearch _cluster/settings API, when queried, could leak\nsensitive configuration information such as passwords, tokens, or\nusernames. This could allow an authenticated Elasticsearch user to\nimproperly view these details.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"\"This issue only afects our security plugin, which was not part of\na default distribution in 1.7\""}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://discuss.elastic.co/t/elastic-stack-6-4-1-and-5-6-12-security-update/149035","https://www.elastic.co/community/security","https://www.cve.org/CVERecord?id=CVE-2018-3831"],"bugs":[""],"patches":{"elasticsearch":[]},"tags":{},"packages":[{"name":"elasticsearch","source":"https://ubuntu.com/security/cve?package=elasticsearch","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=elasticsearch","debian":"https://tracker.debian.org/pkg/elasticsearch","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.4.1, 5.6.12","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3827","published":"2018-09-19T19:29:00","updated_at":"2025-08-25T22:54:20.923035+00:00","description":"\nA sensitive data disclosure flaw was found in the Elasticsearch\nrepository-azure (formerly elasticsearch-cloud-azure) plugin. When the\nrepository-azure plugin is set to log at TRACE level Azure credentials can\nbe inadvertently logged.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/135777","https://www.elastic.co/community/security","https://www.cve.org/CVERecord?id=CVE-2018-3827"],"bugs":[""],"patches":{"elasticsearch":[]},"tags":{},"packages":[{"name":"elasticsearch","source":"https://ubuntu.com/security/cve?package=elasticsearch","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=elasticsearch","debian":"https://tracker.debian.org/pkg/elasticsearch","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3826","published":"2018-09-19T19:29:00","updated_at":"2025-08-25T22:54:20.923035+00:00","description":"\nIn Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found\nin the _snapshot API. When the access_key and security_key parameters are\nset using the _snapshot API they can be exposed as plain text by users able\nto query the _snapshot API.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://discuss.elastic.co/t/elastic-stack-6-3-0-and-5-6-10-security-update/135777","https://www.elastic.co/community/security","https://www.cve.org/CVERecord?id=CVE-2018-3826"],"bugs":[""],"patches":{"elasticsearch":[]},"tags":{},"packages":[{"name":"elasticsearch","source":"https://ubuntu.com/security/cve?package=elasticsearch","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=elasticsearch","debian":"https://tracker.debian.org/pkg/elasticsearch","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"6.3.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-8017","published":"2018-09-19T14:29:00","updated_at":"2025-08-26T12:10:05.440673+00:00","description":"\nIn Apache Tika 1.2 to 1.18, a carefully crafted file can trigger an\ninfinite loop in the IptcAnpaParser.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2018/09/19/6","https://lists.apache.org/thread.html/72df7a3f0dda49a912143a1404b489837a11f374dfd1961061873a91@%3Cdev.tika.apache.org%3E","https://www.cve.org/CVERecord?id=CVE-2018-8017"],"bugs":[""],"patches":{"tika":[]},"tags":{},"packages":[{"name":"tika","source":"https://ubuntu.com/security/cve?package=tika","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tika","debian":"https://tracker.debian.org/pkg/tika","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.20-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.22-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-3574","published":"2018-09-19T14:29:00","updated_at":"2025-08-25T22:54:16.304588+00:00","description":"\nIn all android releases (Android for MSM, Firefox OS for MSM, QRD Android)\nfrom CAF using the linux kernel, userspace can request ION cache\nmaintenance on a secure ION buffer for which the ION_FLAG_SECURE ion flag\nis not set and cause the kernel to attempt to perform cache maintenance on\nmemory which does not belong to HLOS.","ubuntu_description":"","notes":[{"author":"sbeattie","note":"issue is in ION secure heap, which is not upstream"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://source.codeaurora.org/quic/la/kernel/msm-3.10/commit/?id=3286b75d91519073d2f20bee85f22e294d5f1a18","https://source.codeaurora.org/quic/la/kernel/msm-4.4/commit/?id=09874396dfbf546e5a628d810fcf5ea51a4d5785","https://source.codeaurora.org/quic/la/kernel/msm-4.9/commit/?id=53261410da625aaa2e070555aaa150a8533e5be4","https://support.blackberry.com/kb/articleDetail?language=en_US&articleNumber=000049462","https://www.codeaurora.org/security-bulletin/2018/09/04/september-2018-code-aurora-security-bulletin","https://www.cve.org/CVERecord?id=CVE-2018-3574"],"bugs":[""],"patches":{"linux":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-azure-edge":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[]},"tags":{},"packages":[{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-11762","published":"2018-09-19T14:29:00","updated_at":"2025-08-26T12:03:55.131776+00:00","description":"\nIn Apache Tika 0.9 to 1.18, in a rare edge case where a user does not\nspecify an extract directory on the commandline (--extract-dir=) and the\ninput file has an embedded file with an absolute path, such as\n\"C:/evil.bat\", tika-app would overwrite that file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2018/09/19/5","https://lists.apache.org/thread.html/ab2e1af38975f5fc462ba89b517971ef892ec3d06bee12ea2258895b@%3Cdev.tika.apache.org%3E","https://www.cve.org/CVERecord?id=CVE-2018-11762"],"bugs":[""],"patches":{"tika":[]},"tags":{},"packages":[{"name":"tika","source":"https://ubuntu.com/security/cve?package=tika","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tika","debian":"https://tracker.debian.org/pkg/tika","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.20-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.22-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-11761","published":"2018-09-19T14:29:00","updated_at":"2025-08-26T12:03:55.131776+00:00","description":"\nIn Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit\nentity expansion. They were therefore vulnerable to an entity expansion\nvulnerability which can lead to a denial of service attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2018/09/19/4","https://lists.apache.org/thread.html/5553e10bba5604117967466618f219c0cae710075819c70cfb3fb421@%3Cdev.tika.apache.org%3E","https://www.cve.org/CVERecord?id=CVE-2018-11761"],"bugs":[""],"patches":{"tika":[]},"tags":{},"packages":[{"name":"tika","source":"https://ubuntu.com/security/cve?package=tika","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tika","debian":"https://tracker.debian.org/pkg/tika","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.22-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.20-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.22-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-17206","published":"2018-09-19T00:00:00","updated_at":"2025-08-25T22:49:45.787639+00:00","description":"\nAn issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6. The\ndecode_bundle function inside lib/ofp-actions.c is affected by a buffer\nover-read issue during BUNDLE action decoding.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3873-1","https://www.cve.org/CVERecord?id=CVE-2018-17206"],"bugs":[""],"patches":{"openvswitch":["upstream: https://github.com/openvswitch/ovs/commit/5026a263d7846077eee540de42192d27da513226","upstream: https://github.com/openvswitch/ovs/commit/20626d38c1a1d4cebb5a6911ea3cb6a7f4f993f8","upstream: https://github.com/openvswitch/ovs/commit/9237a63c47bd314b807cda0bd2216264e82edbe8","upstream: https://github.com/openvswitch/ovs/commit/e1b5444c2f2ed4bda2c75597468f067ae104319d","upstream: https://github.com/openvswitch/ovs/commit/d69fee374bc94fa4ff9836aef7b2855a565dd83f"]},"tags":{},"packages":[{"name":"openvswitch","source":"https://ubuntu.com/security/cve?package=openvswitch","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openvswitch","debian":"https://tracker.debian.org/pkg/openvswitch","statuses":[{"release_codename":"bionic","status":"released","description":"2.9.2-0ubuntu0.18.04.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.10.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.5.5-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":["USN-3873-1"],"notices":[{"id":"USN-3873-1","title":"Open vSwitch vulnerabilities","summary":"Several security issues were fixed in Open vSwitch.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-01-30T12:33:52.994755","description":"It was discovered that Open vSwitch incorrectly decoded certain packets. A\nremote attacker could possibly use this issue to cause Open vSwitch to\ncrash, resulting in a denial of service. (CVE-2018-17204)\n\nIt was discovered that Open vSwitch incorrectly handled processing certain\nflows. A remote attacker could possibly use this issue to cause Open\nvSwitch to crash, resulting in a denial of service. This issue only\naffected Ubuntu 18.04 LTS. (CVE-2018-17205)\n\nIt was discovered that Open vSwitch incorrectly handled BUNDLE action\ndecoding. A remote attacker could possibly use this issue to cause Open\nvSwitch to crash, resulting in a denial of service. (CVE-2018-17206)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"openvswitch","version":"2.9.2-0ubuntu0.18.04.3","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-doc","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-pki","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-switch","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-test","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-vtep","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-central","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-common","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-controller-vtep","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-docker","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-host","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"python-openvswitch","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"python3-openvswitch","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"}],"xenial":[{"name":"openvswitch","version":"2.5.5-0ubuntu0.16.04.2","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-ipsec","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-pki","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-switch","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-test","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-vtep","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-central","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-common","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-docker","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-host","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"python-openvswitch","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-17204","CVE-2018-17205","CVE-2018-17206"]}]},{"id":"CVE-2018-17205","published":"2018-09-19T00:00:00","updated_at":"2025-08-25T22:49:45.787639+00:00","description":"\nAn issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6,\naffecting ofproto_rule_insert__ in ofproto/ofproto.c. During bundle commit,\nflows that are added in a bundle are applied to ofproto in order. If a flow\ncannot be added (e.g., the flow action is a go-to for a group id that does\nnot exist), OvS tries to revert back all previous flows that were\nsuccessfully applied from the same bundle. This is possible since OvS\nmaintains list of old flows that were replaced by flows from the bundle.\nWhile reinserting old flows, OvS has an assertion failure due to a check on\nrule state != RULE_INITIALIZED. This would work for new flows, but for an\nold flow the rule state is RULE_REMOVED. The assertion failure causes an\nOvS crash.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3873-1","https://www.cve.org/CVERecord?id=CVE-2018-17205"],"bugs":[""],"patches":{"openvswitch":["upstream: https://github.com/openvswitch/ovs/commit/9a0ac025de9303334688ff08f01fc08604d2f624","upstream: https://github.com/openvswitch/ovs/commit/638d406e3b647359f3d82189d7a6ee56b4a54928","upstream: https://github.com/openvswitch/ovs/commit/0befd1f3745055c32940f5faf9559be6a14395e6","upstream: https://github.com/openvswitch/ovs/commit/24bf63b2132fa1d170c1f5594cb74ffa8e924092"]},"tags":{},"packages":[{"name":"openvswitch","source":"https://ubuntu.com/security/cve?package=openvswitch","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openvswitch","debian":"https://tracker.debian.org/pkg/openvswitch","statuses":[{"release_codename":"bionic","status":"released","description":"2.9.2-0ubuntu0.18.04.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.10.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":["USN-3873-1"],"notices":[{"id":"USN-3873-1","title":"Open vSwitch vulnerabilities","summary":"Several security issues were fixed in Open vSwitch.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-01-30T12:33:52.994755","description":"It was discovered that Open vSwitch incorrectly decoded certain packets. A\nremote attacker could possibly use this issue to cause Open vSwitch to\ncrash, resulting in a denial of service. (CVE-2018-17204)\n\nIt was discovered that Open vSwitch incorrectly handled processing certain\nflows. A remote attacker could possibly use this issue to cause Open\nvSwitch to crash, resulting in a denial of service. This issue only\naffected Ubuntu 18.04 LTS. (CVE-2018-17205)\n\nIt was discovered that Open vSwitch incorrectly handled BUNDLE action\ndecoding. A remote attacker could possibly use this issue to cause Open\nvSwitch to crash, resulting in a denial of service. (CVE-2018-17206)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"openvswitch","version":"2.9.2-0ubuntu0.18.04.3","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-doc","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-pki","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-switch","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-test","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-vtep","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-central","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-common","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-controller-vtep","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-docker","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-host","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"python-openvswitch","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"python3-openvswitch","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"}],"xenial":[{"name":"openvswitch","version":"2.5.5-0ubuntu0.16.04.2","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-ipsec","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-pki","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-switch","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-test","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-vtep","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-central","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-common","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-docker","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-host","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"python-openvswitch","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-17204","CVE-2018-17205","CVE-2018-17206"]}]},{"id":"CVE-2018-17204","published":"2018-09-19T00:00:00","updated_at":"2025-08-25T22:49:45.787639+00:00","description":"\nAn issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6,\naffecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When\ndecoding a group mod, it validates the group type and command after the\nwhole group mod has been decoded. The OF1.5 decoder, however, tries to use\nthe type and command earlier, when it might still be invalid. This causes\nan assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable\nsupport for OpenFlow 1.5 by default.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"openflow 1.5 not enabled by default"}],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3873-1","https://www.cve.org/CVERecord?id=CVE-2018-17204"],"bugs":[""],"patches":{"openvswitch":["upstream: https://github.com/openvswitch/ovs/commit/9740d81d94888cb158fa99a9366fe2b32b3e4aaa","upstream: https://github.com/openvswitch/ovs/commit/8976ea1d680ab7a2d726a50e5666aa8fefd24168","upstream: https://github.com/openvswitch/ovs/commit/4af6da3b275b764b1afe194df6499b33d2bf4cde","upstream: https://github.com/openvswitch/ovs/commit/0e6eb58f53d63b79d3a8c6936b0ef72cdd082bdb","upstream: https://github.com/openvswitch/ovs/commit/94b443070fea2a15bc4768c35d59d46892cdc901"]},"tags":{},"packages":[{"name":"openvswitch","source":"https://ubuntu.com/security/cve?package=openvswitch","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=openvswitch","debian":"https://tracker.debian.org/pkg/openvswitch","statuses":[{"release_codename":"bionic","status":"released","description":"2.9.2-0ubuntu0.18.04.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.10.0-0ubuntu2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.5.5-0ubuntu0.16.04.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":["USN-3873-1"],"notices":[{"id":"USN-3873-1","title":"Open vSwitch vulnerabilities","summary":"Several security issues were fixed in Open vSwitch.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-01-30T12:33:52.994755","description":"It was discovered that Open vSwitch incorrectly decoded certain packets. A\nremote attacker could possibly use this issue to cause Open vSwitch to\ncrash, resulting in a denial of service. (CVE-2018-17204)\n\nIt was discovered that Open vSwitch incorrectly handled processing certain\nflows. A remote attacker could possibly use this issue to cause Open\nvSwitch to crash, resulting in a denial of service. This issue only\naffected Ubuntu 18.04 LTS. (CVE-2018-17205)\n\nIt was discovered that Open vSwitch incorrectly handled BUNDLE action\ndecoding. A remote attacker could possibly use this issue to cause Open\nvSwitch to crash, resulting in a denial of service. (CVE-2018-17206)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"openvswitch","version":"2.9.2-0ubuntu0.18.04.3","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-doc","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-pki","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-switch","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-test","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"openvswitch-vtep","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-central","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-common","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-controller-vtep","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-docker","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"ovn-host","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"python-openvswitch","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"},{"name":"python3-openvswitch","version":"2.9.2-0ubuntu0.18.04.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.9.2-0ubuntu0.18.04.3","pocket":"security"}],"xenial":[{"name":"openvswitch","version":"2.5.5-0ubuntu0.16.04.2","description":"Ethernet virtual switch","is_source":true},{"name":"openvswitch-common","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-ipsec","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-pki","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-switch","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-switch-dpdk","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-test","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-testcontroller","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"openvswitch-vtep","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-central","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-common","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-docker","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"ovn-host","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"},{"name":"python-openvswitch","version":"2.5.5-0ubuntu0.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openvswitch","version_link":"https://launchpad.net/ubuntu/+source/openvswitch/2.5.5-0ubuntu0.16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-17204","CVE-2018-17205","CVE-2018-17206"]}]},{"id":"CVE-2018-17183","published":"2018-09-19T00:00:00","updated_at":"2025-08-25T22:49:41.529812+00:00","description":"\nArtifex Ghostscript before 9.25 allowed a user-writable error exception\ntable, which could be used by remote attackers able to supply crafted\nPostScript to potentially overwrite or replace error handlers to inject\ncode.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"debian hit a regression with this commit, see debian bug below"}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3773-1","https://www.cve.org/CVERecord?id=CVE-2018-17183"],"bugs":["https://bugs.ghostscript.com/show_bug.cgi?id=699708 (not public)","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=909076"],"patches":{"ghostscript":["upstream: http://git.ghostscript.com/?p=ghostpdl.git;a=commit;h=fb713b3818b52d8a6cf62c951eba2e1795ff9624"]},"tags":{},"packages":[{"name":"ghostscript","source":"https://ubuntu.com/security/cve?package=ghostscript","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ghostscript","debian":"https://tracker.debian.org/pkg/ghostscript","statuses":[{"release_codename":"bionic","status":"released","description":"9.25~dfsg+1-0ubuntu0.18.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"9.25~dfsg+1-0ubuntu0.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.25~dfsg-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"9.25~dfsg+1-0ubuntu0.16.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3773-1"],"notices":[{"id":"USN-3773-1","title":"Ghostscript vulnerabilities","summary":"Several security issues were fixed in Ghostscript.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. In general, a standard system update will make all the necessary\nchanges.\n","references":[],"published":"2018-10-01T12:12:05.187894","description":"It was discovered that Ghostscript contained multiple security issues. If a\nuser or automated system were tricked into processing a specially crafted\nfile, a remote attacker could possibly use these issues to access arbitrary\nfiles, execute arbitrary code, or cause a denial of service.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"ghostscript","version":"9.25~dfsg+1-0ubuntu0.18.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.25~dfsg+1-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.25~dfsg+1-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.18.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.25~dfsg+1-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.25~dfsg+1-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9","version":"9.25~dfsg+1-0ubuntu0.18.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.18.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.25~dfsg+1-0ubuntu0.18.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.18.04.1","pocket":"security"}],"trusty":[{"name":"ghostscript","version":"9.25~dfsg+1-0ubuntu0.14.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.25~dfsg+1-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.25~dfsg+1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.14.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.25~dfsg+1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.25~dfsg+1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9","version":"9.25~dfsg+1-0ubuntu0.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.14.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.25~dfsg+1-0ubuntu0.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.14.04.1","pocket":"security"}],"xenial":[{"name":"ghostscript","version":"9.25~dfsg+1-0ubuntu0.16.04.1","description":"PostScript and PDF interpreter","is_source":true},{"name":"ghostscript","version":"9.25~dfsg+1-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-doc","version":"9.25~dfsg+1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.16.04.1","pocket":"security"},{"name":"ghostscript-x","version":"9.25~dfsg+1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs-dev","version":"9.25~dfsg+1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9","version":"9.25~dfsg+1-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.16.04.1","pocket":"security"},{"name":"libgs9-common","version":"9.25~dfsg+1-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ghostscript","version_link":"https://launchpad.net/ubuntu/+source/ghostscript/9.25~dfsg+1-0ubuntu0.16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-16510","CVE-2018-17183"]}]},{"id":"CVE-2018-17182","published":"2018-09-19T00:00:00","updated_at":"2026-07-04T07:47:49.253203+00:00","description":"\nAn issue was discovered in the Linux kernel through 4.18.8. The\nvmacache_flush_all function in mm/vmacache.c mishandles sequence number\noverflows. An attacker can trigger a use-after-free (and possibly gain\nprivileges) via certain thread creation, map, unmap, invalidation, and\ndereference operations.","ubuntu_description":"\nJann Horn discovered that the vmacache subsystem did not properly handle\nsequence number overflows, leading to a use-after-free vulnerability. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code.","notes":[{"author":"sbeattie","note":"as of 2018-09-26, fixes for this issue are applied to all\nkernels uploaded to RELEASE-proposed today. and should be released\naround Monday, Oct 1, 2018."}],"codename":null,"priority":"high","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://googleprojectzero.blogspot.com/2018/09/a-cache-invalidation-bug-in-linux.html","https://ubuntu.com/security/notices/USN-3776-1","https://ubuntu.com/security/notices/USN-3776-2","https://ubuntu.com/security/notices/USN-3777-1","https://ubuntu.com/security/notices/USN-3777-2","https://ubuntu.com/security/notices/USN-3777-3","https://www.cve.org/CVERecord?id=CVE-2018-17182"],"bugs":[""],"patches":{"linux":["break-fix: 6b4ebc3a9078c5b7b8c4cf495a0b1d2d0e0bfe7a 7a9cdebdcc17e426fb5287e4a82db1dfe86339b2"],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-azure-edge":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-hwe-5.4":[],"linux-hwe-5.15":[],"linux-hwe-6.8":[],"linux-aws-5.4":[],"linux-aws-5.15":[],"linux-aws-hwe":[],"linux-azure-4.15":[],"linux-azure-5.4":[],"linux-azure-5.15":[],"linux-azure-fde":[],"linux-azure-fde-5.15":[],"linux-bluefield":[],"linux-fips":[],"linux-aws-fips":[],"linux-azure-fips":[],"linux-gcp-fips":[],"linux-gcp-4.15":[],"linux-gcp-5.4":[],"linux-gcp-5.15":[],"linux-gkeop":[],"linux-gkeop-5.15":[],"linux-ibm":[],"linux-ibm-5.4":[],"linux-ibm-5.15":[],"linux-intel":[],"linux-intel-iotg":[],"linux-intel-iotg-5.15":[],"linux-iot":[],"linux-intel-iot-realtime":[],"linux-lowlatency":[],"linux-lowlatency-hwe-5.15":[],"linux-lowlatency-hwe-6.8":[],"linux-nvidia":[],"linux-nvidia-6.5":[],"linux-nvidia-6.8":[],"linux-nvidia-lowlatency":[],"linux-oracle":[],"linux-oracle-5.4":[],"linux-oracle-5.15":[],"linux-oem-6.8":[],"linux-raspi":[],"linux-raspi-5.4":[],"linux-raspi-realtime":[],"linux-realtime":[],"linux-riscv":[],"linux-riscv-5.15":[],"linux-riscv-6.8":[],"linux-xilinx-zynqmp":[],"linux-aws-6.8":[],"linux-gcp-6.8":[],"linux-oracle-6.8":[],"linux-azure-6.8":[],"linux-oem-6.11":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux-aws-fips","source":"https://ubuntu.com/security/cve?package=linux-aws-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-fips","debian":"https://tracker.debian.org/pkg/linux-aws-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1052.57+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-2000.4","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips2","component":null,"pocket":"fips"}]},{"name":"linux-azure-fips","source":"https://ubuntu.com/security/cve?package=linux-azure-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-fips","debian":"https://tracker.debian.org/pkg/linux-azure-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1058.66+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1022.22+fips1","component":null,"pocket":"fips"}]},{"name":"linux-gcp-fips","source":"https://ubuntu.com/security/cve?package=linux-gcp-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-fips","debian":"https://tracker.debian.org/pkg/linux-gcp-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1048.56+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips1","component":null,"pocket":"fips"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-36.39","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.18.0-9.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-137.163","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-10.11","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-9.12","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-19.19","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"3.11.0-12.19","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1023.23","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.18.0-1002.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-1031.34","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1069.79","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1002.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1008.8","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1008.8","component":null,"pocket":"security"}]},{"name":"linux-aws-5.15","source":"https://ubuntu.com/security/cve?package=linux-aws-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.15","debian":"https://tracker.debian.org/pkg/linux-aws-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.19~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-5.4","source":"https://ubuntu.com/security/cve?package=linux-aws-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.4","debian":"https://tracker.debian.org/pkg/linux-aws-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1020.20~18.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-6.8","source":"https://ubuntu.com/security/cve?package=linux-aws-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.8","debian":"https://tracker.debian.org/pkg/linux-aws-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1009.9~22.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1031.33~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1025.26","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.18.0-1003.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.15.0-1031.32~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1025.26~16.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1003.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1006.6","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1006.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1082.92","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.8~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1022.22~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-6.8","source":"https://ubuntu.com/security/cve?package=linux-azure-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.8","debian":"https://tracker.debian.org/pkg/linux-azure-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.18.0-1004.4~18.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde","source":"https://ubuntu.com/security/cve?package=linux-azure-fde","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde","debian":"https://tracker.debian.org/pkg/linux-azure-fde","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1019.24.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1041.48","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-azure-fde-5.15]","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-fde-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1019.24~20.04.1.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-bluefield","source":"https://ubuntu.com/security/cve?package=linux-bluefield","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-bluefield","debian":"https://tracker.debian.org/pkg/linux-bluefield","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1011.14","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"}]},{"name":"linux-fips","source":"https://ubuntu.com/security/cve?package=linux-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fips","debian":"https://tracker.debian.org/pkg/linux-fips","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-92.102+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1017.22~recert1","component":null,"pocket":"fips"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1011.12","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.8","component":null,"pocket":"fips"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1021.22","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.18.0-1002.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1021.22~16.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1002.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1071.81","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.15","debian":"https://tracker.debian.org/pkg/linux-gcp-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1006.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.4","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.4","debian":"https://tracker.debian.org/pkg/linux-gcp-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.8","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.8","debian":"https://tracker.debian.org/pkg/linux-gcp-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1010.11~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.5","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop","source":"https://ubuntu.com/security/cve?package=linux-gkeop","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gkeop","debian":"https://tracker.debian.org/pkg/linux-gkeop","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1008.9","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop-5.15","source":"https://ubuntu.com/security/cve?package=linux-gkeop-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gkeop-5.15","debian":"https://tracker.debian.org/pkg/linux-gkeop-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-36.39~16.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-37.41~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-36.39~16.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.0.0-15.16~18.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm","source":"https://ubuntu.com/security/cve?package=linux-ibm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm","debian":"https://tracker.debian.org/pkg/linux-ibm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1009.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.15","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.15","debian":"https://tracker.debian.org/pkg/linux-ibm-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1034.37~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.4","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.4","debian":"https://tracker.debian.org/pkg/linux-ibm-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1010.11~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel","source":"https://ubuntu.com/security/cve?package=linux-intel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel","debian":"https://tracker.debian.org/pkg/linux-intel","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iot-realtime","source":"https://ubuntu.com/security/cve?package=linux-intel-iot-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel-iot-realtime","debian":"https://tracker.debian.org/pkg/linux-intel-iot-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1021.26","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg","debian":"https://tracker.debian.org/pkg/linux-intel-iotg","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1004.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg-5.15","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg-5.15","debian":"https://tracker.debian.org/pkg/linux-intel-iotg-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-iot","source":"https://ubuntu.com/security/cve?package=linux-iot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-iot","debian":"https://tracker.debian.org/pkg/linux-iot","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1023.23","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.18.0-1003.3","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1035.41","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1003.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency","debian":"https://tracker.debian.org/pkg/linux-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-22.22","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-137.163~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-nvidia","source":"https://ubuntu.com/security/cve?package=linux-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia","debian":"https://tracker.debian.org/pkg/linux-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1005.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.5","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.5","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.5.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.8","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.8","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-nvidia-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-lowlatency","debian":"https://tracker.debian.org/pkg/linux-nvidia-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1009.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1021.24","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1021.24","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1021.24","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.11","source":"https://ubuntu.com/security/cve?package=linux-oem-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.11","debian":"https://tracker.debian.org/pkg/linux-oem-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"}]},{"name":"linux-oem-6.8","source":"https://ubuntu.com/security/cve?package=linux-oem-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.8","debian":"https://tracker.debian.org/pkg/linux-oem-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1010.10","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1008.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1008.10~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1005.5","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.15","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.15","debian":"https://tracker.debian.org/pkg/linux-oracle-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.4","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.4","debian":"https://tracker.debian.org/pkg/linux-oracle-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.8","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.8","debian":"https://tracker.debian.org/pkg/linux-oracle-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1006.6~22.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1005.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1013.13~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi-realtime","source":"https://ubuntu.com/security/cve?package=linux-raspi-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi-realtime","debian":"https://tracker.debian.org/pkg/linux-raspi-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.7.0-2001.1","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1024.26","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.18.0-1005.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1098.106","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1005.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [replaced by linux-raspi]","component":null,"pocket":"security"}]},{"name":"linux-realtime","source":"https://ubuntu.com/security/cve?package=linux-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-realtime","debian":"https://tracker.debian.org/pkg/linux-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1006.6","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.1-1015.16","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-riscv-5.8]","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.15","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.15","debian":"https://tracker.debian.org/pkg/linux-riscv-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.17~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.8","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.8","debian":"https://tracker.debian.org/pkg/linux-riscv-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1102.107","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-xilinx-zynqmp","source":"https://ubuntu.com/security/cve?package=linux-xilinx-zynqmp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-xilinx-zynqmp","debian":"https://tracker.debian.org/pkg/linux-xilinx-zynqmp","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1020.24","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1022.26","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.19~rc4, 4.4.157","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3776-1","USN-3776-2","USN-3777-2","USN-3777-1","USN-3777-3"],"notices":[{"id":"USN-3776-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-10-01T18:49:15.275876","description":"Jann Horn discovered that the vmacache subsystem did not properly handle\nsequence number overflows, leading to a use-after-free vulnerability. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code. (CVE-2018-17182)\n\nIt was discovered that the paravirtualization implementation in the Linux\nkernel did not properly handle some indirect calls, reducing the\neffectiveness of Spectre v2 mitigations for paravirtual guests. A local\nattacker could use this to expose sensitive information. (CVE-2018-15594)\n\nIt was discovered that microprocessors utilizing speculative execution and\nprediction of return addresses via Return Stack Buffer (RSB) may allow\nunauthorized memory reads via sidechannel attacks. An attacker could use\nthis to expose sensitive information. (CVE-2018-15572)\n\nIt was discovered that a NULL pointer dereference could be triggered in the\nOCFS2 file system implementation in the Linux kernel. A local attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2017-18216)\n\nIt was discovered that a race condition existed in the raw MIDI driver for\nthe Linux kernel, leading to a double free vulnerability. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2018-10902)\n\nIt was discovered that a stack-based buffer overflow existed in the iSCSI\ntarget implementation of the Linux kernel. A remote attacker could use this\nto cause a denial of service (system crash). (CVE-2018-14633)\n\nIt was discovered that the YUREX USB device driver for the Linux kernel did\nnot properly restrict user space reads or writes. A physically proximate\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2018-16276)\n\nIt was discovered that a memory leak existed in the IRDA subsystem of the\nLinux kernel. A local attacker could use this to cause a denial of service\n(kernel memory exhaustion). (CVE-2018-6554)\n\nIt was discovered that a use-after-free vulnerability existed in the IRDA\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-6555)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux","version":"4.4.0-137.163","description":"Linux kernel","is_source":true},{"name":"linux-aws","version":"4.4.0-1069.79","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-kvm","version":"4.4.0-1035.41","description":"Linux kernel for cloud environments","is_source":true},{"name":"linux-raspi2","version":"4.4.0-1098.106","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-snapdragon","version":"4.4.0-1102.107","description":"Linux kernel for Snapdragon processors","is_source":true},{"name":"linux-image-4.4.0-1035-kvm","version":"4.4.0-1035.41","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-kvm","version_link":"https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1035.41","pocket":"security"},{"name":"linux-image-4.4.0-1069-aws","version":"4.4.0-1069.79","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1069.79","pocket":"security"},{"name":"linux-image-4.4.0-1098-raspi2","version":"4.4.0-1098.106","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1098.106","pocket":"security"},{"name":"linux-image-4.4.0-1102-snapdragon","version":"4.4.0-1102.107","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon","version_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1102.107","pocket":"security"},{"name":"linux-image-4.4.0-137-generic","version":"4.4.0-137.163","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-137.163","pocket":"security"},{"name":"linux-image-4.4.0-137-generic-lpae","version":"4.4.0-137.163","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-137.163","pocket":"security"},{"name":"linux-image-4.4.0-137-lowlatency","version":"4.4.0-137.163","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-137.163","pocket":"security"},{"name":"linux-image-4.4.0-137-powerpc-e500mc","version":"4.4.0-137.163","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-137.163","pocket":"security"},{"name":"linux-image-4.4.0-137-powerpc-smp","version":"4.4.0-137.163","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-137.163","pocket":"security"},{"name":"linux-image-4.4.0-137-powerpc64-emb","version":"4.4.0-137.163","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-137.163","pocket":"security"},{"name":"linux-image-4.4.0-137-powerpc64-smp","version":"4.4.0-137.163","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-137.163","pocket":"security"},{"name":"linux-image-extra-4.4.0-137-generic","version":"4.4.0-137.163","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-137.163","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-18216","CVE-2018-10902","CVE-2018-14633","CVE-2018-15572","CVE-2018-15594","CVE-2018-16276","CVE-2018-17182","CVE-2018-6554","CVE-2018-6555"]},{"id":"USN-3776-2","title":"Linux kernel (Xenial HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-10-01T18:52:21.756800","description":"USN-3776-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu\n14.04 LTS.\n\nJann Horn discovered that the vmacache subsystem did not properly handle\nsequence number overflows, leading to a use-after-free vulnerability. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code. (CVE-2018-17182)\n\nIt was discovered that the paravirtualization implementation in the Linux\nkernel did not properly handle some indirect calls, reducing the\neffectiveness of Spectre v2 mitigations for paravirtual guests. A local\nattacker could use this to expose sensitive information. (CVE-2018-15594)\n\nIt was discovered that microprocessors utilizing speculative execution and\nprediction of return addresses via Return Stack Buffer (RSB) may allow\nunauthorized memory reads via sidechannel attacks. An attacker could use\nthis to expose sensitive information. (CVE-2018-15572)\n\nIt was discovered that a NULL pointer dereference could be triggered in the\nOCFS2 file system implementation in the Linux kernel. A local attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2017-18216)\n\nIt was discovered that a race condition existed in the raw MIDI driver for\nthe Linux kernel, leading to a double free vulnerability. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2018-10902)\n\nIt was discovered that a stack-based buffer overflow existed in the iSCSI\ntarget implementation of the Linux kernel. A remote attacker could use this\nto cause a denial of service (system crash). (CVE-2018-14633)\n\nIt was discovered that the YUREX USB device driver for the Linux kernel did\nnot properly restrict user space reads or writes. A physically proximate\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2018-16276)\n\nIt was discovered that a memory leak existed in the IRDA subsystem of the\nLinux kernel. A local attacker could use this to cause a denial of service\n(kernel memory exhaustion). (CVE-2018-6554)\n\nIt was discovered that a use-after-free vulnerability existed in the IRDA\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-6555)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-aws","version":"4.4.0-1031.34","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-lts-xenial","version":"4.4.0-137.163~14.04.1","description":"Linux hardware enablement kernel from Xenial for Trusty","is_source":true},{"name":"linux-image-4.4.0-1031-aws","version":"4.4.0-1031.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1031.34","pocket":"security"},{"name":"linux-image-4.4.0-137-generic","version":"4.4.0-137.163~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-137.163~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-137-generic-lpae","version":"4.4.0-137.163~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-137.163~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-137-lowlatency","version":"4.4.0-137.163~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-137.163~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-137-powerpc-e500mc","version":"4.4.0-137.163~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-137.163~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-137-powerpc-smp","version":"4.4.0-137.163~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-137.163~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-137-powerpc64-emb","version":"4.4.0-137.163~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-137.163~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-137-powerpc64-smp","version":"4.4.0-137.163~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-137.163~14.04.1","pocket":"security"},{"name":"linux-image-extra-4.4.0-137-generic","version":"4.4.0-137.163~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-137.163~14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-18216","CVE-2018-10902","CVE-2018-14633","CVE-2018-15572","CVE-2018-15594","CVE-2018-16276","CVE-2018-17182","CVE-2018-6554","CVE-2018-6555"]},{"id":"USN-3777-2","title":"Linux kernel (HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":["https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Variant4"],"published":"2018-10-01T19:24:58.316016","description":"USN-3777-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu\n16.04 LTS.\n\nJann Horn discovered that the vmacache subsystem did not properly handle\nsequence number overflows, leading to a use-after-free vulnerability. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code. (CVE-2018-17182)\n\nIt was discovered that the paravirtualization implementation in the Linux\nkernel did not properly handle some indirect calls, reducing the\neffectiveness of Spectre v2 mitigations for paravirtual guests. A local\nattacker could use this to expose sensitive information. (CVE-2018-15594)\n\nIt was discovered that microprocessors utilizing speculative execution and\nprediction of return addresses via Return Stack Buffer (RSB) may allow\nunauthorized memory reads via sidechannel attacks. An attacker could use\nthis to expose sensitive information. (CVE-2018-15572)\n\nAndy Lutomirski and Mika Penttilä discovered that the KVM implementation\nin the Linux kernel did not properly check privilege levels when emulating\nsome instructions. An unprivileged attacker in a guest VM could use this to\nescalate privileges within the guest. (CVE-2018-10853)\n\nIt was discovered that a stack-based buffer overflow existed in the iSCSI\ntarget implementation of the Linux kernel. A remote attacker could use this\nto cause a denial of service (system crash). (CVE-2018-14633)\n\nIt was discovered that a memory leak existed in the IRDA subsystem of the\nLinux kernel. A local attacker could use this to cause a denial of service\n(kernel memory exhaustion). (CVE-2018-6554)\n\nIt was discovered that a use-after-free vulnerability existed in the IRDA\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-6555)\n\nUSN 3653-2 added a mitigation for Speculative Store Bypass\na.k.a. Spectre Variant 4 (CVE-2018-3639). This update provides the\ncorresponding mitigation for ARM64 processors. Please note that for\nthis mitigation to be effective, an updated firmware for the processor\nmay be required.\n'","is_hidden":false,"release_packages":{"xenial":[{"name":"linux-gcp","version":"4.15.0-1021.22~16.04.1","description":"Linux kernel for Google Cloud Platform (GCP) systems","is_source":true},{"name":"linux-hwe","version":"4.15.0-36.39~16.04.1","description":"Linux hardware enablement (HWE) kernel","is_source":true},{"name":"linux-image-4.15.0-36-generic","version":"4.15.0-36.39~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-36.39~16.04.1","pocket":"security"},{"name":"linux-image-4.15.0-36-generic-lpae","version":"4.15.0-36.39~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-36.39~16.04.1","pocket":"security"},{"name":"linux-image-4.15.0-36-lowlatency","version":"4.15.0-36.39~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-36.39~16.04.1","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-1021-gcp","version":"4.15.0-1021.22~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1021.22~16.04.1","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-36-generic","version":"4.15.0-36.39~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-36.39~16.04.1","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-36-lowlatency","version":"4.15.0-36.39~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-36.39~16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-10853","CVE-2018-14633","CVE-2018-15572","CVE-2018-15594","CVE-2018-17182","CVE-2018-6554","CVE-2018-6555"]},{"id":"USN-3777-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":["https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Variant4"],"published":"2018-10-01T19:15:42.706100","description":"Jann Horn discovered that the vmacache subsystem did not properly handle\nsequence number overflows, leading to a use-after-free vulnerability. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code. (CVE-2018-17182)\n\nIt was discovered that the paravirtualization implementation in the Linux\nkernel did not properly handle some indirect calls, reducing the\neffectiveness of Spectre v2 mitigations for paravirtual guests. A local\nattacker could use this to expose sensitive information. (CVE-2018-15594)\n\nIt was discovered that microprocessors utilizing speculative execution and\nprediction of return addresses via Return Stack Buffer (RSB) may allow\nunauthorized memory reads via sidechannel attacks. An attacker could use\nthis to expose sensitive information. (CVE-2018-15572)\n\nAndy Lutomirski and Mika Penttilä discovered that the KVM implementation\nin the Linux kernel did not properly check privilege levels when emulating\nsome instructions. An unprivileged attacker in a guest VM could use this to\nescalate privileges within the guest. (CVE-2018-10853)\n\nIt was discovered that a stack-based buffer overflow existed in the iSCSI\ntarget implementation of the Linux kernel. A remote attacker could use this\nto cause a denial of service (system crash). (CVE-2018-14633)\n\nIt was discovered that a memory leak existed in the IRDA subsystem of the\nLinux kernel. A local attacker could use this to cause a denial of service\n(kernel memory exhaustion). (CVE-2018-6554)\n\nIt was discovered that a use-after-free vulnerability existed in the IRDA\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-6555)\n\nUSN 3652-1 added a mitigation for Speculative Store Bypass\na.k.a. Spectre Variant 4 (CVE-2018-3639). This update provides the\ncorresponding mitigation for ARM64 processors. Please note that for\nthis mitigation to be effective, an updated firmware for the processor\nmay be required.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"linux","version":"4.15.0-36.39","description":"Linux kernel","is_source":true},{"name":"linux-aws","version":"4.15.0-1023.23","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-gcp","version":"4.15.0-1021.22","description":"Linux kernel for Google Cloud Platform (GCP) systems","is_source":true},{"name":"linux-kvm","version":"4.15.0-1023.23","description":"Linux kernel for cloud environments","is_source":true},{"name":"linux-oem","version":"4.15.0-1021.24","description":"Linux kernel for OEM processors","is_source":true},{"name":"linux-raspi2","version":"4.15.0-1024.26","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-image-4.15.0-1023-aws","version":"4.15.0-1023.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1023.23","pocket":"security"},{"name":"linux-image-4.15.0-1023-kvm","version":"4.15.0-1023.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1023.23","pocket":"security"},{"name":"linux-image-4.15.0-1024-raspi2","version":"4.15.0-1024.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1024.26","pocket":"security"},{"name":"linux-image-4.15.0-36-generic","version":"4.15.0-36.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-36.39","pocket":"security"},{"name":"linux-image-4.15.0-36-generic-lpae","version":"4.15.0-36.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-36.39","pocket":"security"},{"name":"linux-image-4.15.0-36-lowlatency","version":"4.15.0-36.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-36.39","pocket":"security"},{"name":"linux-image-4.15.0-36-snapdragon","version":"4.15.0-36.39","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-36.39","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-1021-gcp","version":"4.15.0-1021.22","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1021.22","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-1021-oem","version":"4.15.0-1021.24","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-oem","version_link":"https://launchpad.net/ubuntu/+source/linux-oem/4.15.0-1021.24","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-36-generic","version":"4.15.0-36.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-36.39","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-36-lowlatency","version":"4.15.0-36.39","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-36.39","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-10853","CVE-2018-14633","CVE-2018-15572","CVE-2018-15594","CVE-2018-17182","CVE-2018-6554","CVE-2018-6555"]},{"id":"USN-3777-3","title":"Linux kernel (Azure) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-10-23T04:01:36.510059","description":"USN-3777-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04\n%LTS. This update provides the corresponding updates for the\nLinux kernel for Azure Cloud systems.\n\nJann Horn discovered that the vmacache subsystem did not properly handle\nsequence number overflows, leading to a use-after-free vulnerability. A\nlocal attacker could use this to cause a denial of service (system crash)\nor execute arbitrary code. (CVE-2018-17182)\n\nIt was discovered that the paravirtualization implementation in the Linux\nkernel did not properly handle some indirect calls, reducing the\neffectiveness of Spectre v2 mitigations for paravirtual guests. A local\nattacker could use this to expose sensitive information. (CVE-2018-15594)\n\nIt was discovered that microprocessors utilizing speculative execution and\nprediction of return addresses via Return Stack Buffer (RSB) may allow\nunauthorized memory reads via sidechannel attacks. An attacker could use\nthis to expose sensitive information. (CVE-2018-15572)\n\nJann Horn discovered that microprocessors utilizing speculative execution\nand branch prediction may allow unauthorized memory reads via sidechannel\nattacks. This flaw is known as Spectre. A local attacker could use this to\nexpose sensitive information, including kernel memory. (CVE-2017-5715)\n\nIt was discovered that a stack-based buffer overflow existed in the iSCSI\ntarget implementation of the Linux kernel. A remote attacker could use this\nto cause a denial of service (system crash). (CVE-2018-14633)\n\nJann Horn and Ken Johnson discovered that microprocessors utilizing\nspeculative execution of a memory read may allow unauthorized memory reads\nvia a sidechannel attack. This flaw is known as Spectre Variant 4. A local\nattacker could use this to expose sensitive information, including kernel\nmemory. (CVE-2018-3639)\n\nIt was discovered that a memory leak existed in the IRDA subsystem of the\nLinux kernel. A local attacker could use this to cause a denial of service\n(kernel memory exhaustion). (CVE-2018-6554)\n\nIt was discovered that a use-after-free vulnerability existed in the IRDA\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-6555)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"linux-azure","version":"4.15.0-1025.26","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-image-unsigned-4.15.0-1025-azure","version":"4.15.0-1025.26","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1025.26","pocket":"security"}],"xenial":[{"name":"linux-azure","version":"4.15.0-1025.26~16.04.1","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-image-unsigned-4.15.0-1025-azure","version":"4.15.0-1025.26~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1025.26~16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-5715","CVE-2018-14633","CVE-2018-15572","CVE-2018-15594","CVE-2018-17182","CVE-2018-3639","CVE-2018-6554","CVE-2018-6555"]}]},{"id":"CVE-2018-16515","published":"2018-09-18T21:29:00","updated_at":"2025-08-25T22:49:06.308598+00:00","description":"\nMatrix Synapse before 0.33.3.1 allows remote attackers to spoof events and\npossibly have unspecified other impacts by leveraging improper transaction\nand event signature validation.","ubuntu_description":"","notes":[{"author":"msalvatore","note":"This CVE covers a few problems. To exploit the first, you must be\n\"the administrator of any server in a room\". To exploit the second\ntwo requires a \"malicious server\"."}],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://matrix.org/blog/2018/09/05/pre-disclosure-upcoming-critical-security-fix-for-synapse/","https://github.com/matrix-org/synapse/issues/3796","https://matrix.org/blog/2018/09/06/critical-security-update-synapse-0-33-3-1","https://ubuntu.com/security/notices/USN-6076-1","https://www.cve.org/CVERecord?id=CVE-2018-16515"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=908044"],"patches":{"matrix-synapse":[]},"tags":{},"packages":[{"name":"matrix-synapse","source":"https://ubuntu.com/security/cve?package=matrix-synapse","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=matrix-synapse","debian":"https://tracker.debian.org/pkg/matrix-synapse","statuses":[{"release_codename":"groovy","status":"not-affected","description":"0.99.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.99.2-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.99.2-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.99.2-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.99.2-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"0.24.0+dfsg-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.99.2-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.99.2-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.99.2-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.99.2-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.33.3.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-6076-1"],"notices":[{"id":"USN-6076-1","title":"Synapse vulnerabilities","summary":"Several security issues were fixed in Synapse.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-05-16T07:45:08.513146","description":"It was discovered that Synapse incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to cause a\ndenial of service. (CVE-2019-18835, CVE-2018-12291, CVE-2018-10657)\n\nIt was discovered that Synapse incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to hijack the\nsession. (CVE-2019-11842, CVE-2018-12423)\n\nIt was discovered that Synapse incorrectly handled certain inputs. If a\nuser or an automated system were tricked into opening a specially crafted\ninput file, a remote attacker could possibly use this issue to perform \nspoofing or user impersonation. (CVE-2019-5885, CVE-2018-16515)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"matrix-synapse","version":"0.24.0+dfsg-1ubuntu0.1~esm1","description":"Synapse: Matrix homeserver written in Python/Twisted.","is_source":true},{"name":"matrix-synapse","version":"0.24.0+dfsg-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/matrix-synapse","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2019-5885","CVE-2018-12291","CVE-2018-16515","CVE-2018-12423","CVE-2019-11842","CVE-2018-10657","CVE-2019-18835"]}]},{"id":"CVE-2018-13982","published":"2018-09-18T21:29:00","updated_at":"2025-08-25T22:46:59.829691+00:00","description":"\nSmarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to\na path traversal vulnerability due to insufficient template code\nsanitization. This allows attackers controlling the executed template code\nto bypass the trusted directory security restriction and read arbitrary\nfiles.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.openwall.com/lists/oss-security/2018/09/17/4","https://github.com/sbaresearch/advisories/tree/public/2018/SBA-ADV-20180420-01_Smarty_Path_Traversal","https://ubuntu.com/security/notices/USN-5348-1","https://www.cve.org/CVERecord?id=CVE-2018-13982"],"bugs":[""],"patches":{"smarty3":["upstream: https://github.com/smarty-php/smarty/commit/8d21f38dc35c4cd6b31c2f23fc9b8e5adbc56dfe","upstream: https://github.com/smarty-php/smarty/commit/f9ca3c63d1250bb56b2bda609dcc9dd81f0065f8","upstream: https://github.com/smarty-php/smarty/commit/2e081a51b1effddb23f87952959139ac62654d50","upstream: https://github.com/smarty-php/smarty/commit/c9dbe1d08c081912d02bd851d1d1b6388f6133d1"]},"tags":{},"packages":[{"name":"smarty3","source":"https://ubuntu.com/security/cve?package=smarty3","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=smarty3","debian":"https://tracker.debian.org/pkg/smarty3","statuses":[{"release_codename":"bionic","status":"released","description":"3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.1.33+20180830.1.3a78a21f+selfpack1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.1.33+20180830.1.3a78a21f+selfpack1-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.1.33+20180830.1.3a78a21f+selfpack1-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.1.33+20180830.1.3a78a21f+selfpack1-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.1.33+20180830.1.3a78a21f+selfpack1-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.1.33+20180830.1.3a78a21f+selfpack1-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.1.33+20180830.1.3a78a21f+selfpack1-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.1.33","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-5348-1"],"notices":[{"id":"USN-5348-1","title":"Smarty vulnerabilities","summary":"Several security issues were fixed in Smarty.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2022-03-28T10:09:49.684650","description":"David Gnedt and Thomas Konrad discovered that Smarty was incorrectly\nsanitizing the paths present in the templates. An attacker could possibly\nuse this use to read arbitrary files when controlling the executed\ntemplate. (CVE-2018-13982)\n\nIt was discovered that Smarty was incorrectly sanitizing the paths\npresent in the templates. An attacker could possibly use this use to read\narbitrary files when controlling the executed template. (CVE-2018-16831)\n\nIt was discovered that Smarty was incorrectly validating security policy\ndata, allowing the execution of static classes even when not permitted by\nthe security settings. An attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2021-21408)\n\nIt was discovered that Smarty was incorrectly managing access control to\ntemplate objects, which allowed users to perform a sandbox escape. An\nattacker could possibly use this issue to send specially crafted input to\napplications that use Smarty and execute arbitrary code. (CVE-2021-26119)\n\nIt was discovered that Smarty was not checking for special characters\nwhen setting function names during plugin compile operations. An attacker\ncould possibly use this issue to send specially crafted input to\napplications that use Smarty and execute arbitrary code. (CVE-2021-26120)\n\nIt was discovered that Smarty was incorrectly sanitizing characters in\nmath strings processed by the math function. An attacker could possibly\nuse this issue to send specially crafted input to applications that use\nSmarty and execute arbitrary code. (CVE-2021-29454)\n","is_hidden":false,"release_packages":{"impish":[{"name":"smarty3","version":"3.1.39-2ubuntu0.21.10.1","description":"The compiling PHP template engine","is_source":true},{"name":"smarty3","version":"3.1.39-2ubuntu0.21.10.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/smarty3","version_link":"https://launchpad.net/ubuntu/+source/smarty3/3.1.39-2ubuntu0.21.10.1","pocket":"security"}],"bionic":[{"name":"smarty3","version":"3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1","description":"The compiling PHP template engine","is_source":true},{"name":"smarty3","version":"3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/smarty3","version_link":"https://launchpad.net/ubuntu/+source/smarty3/3.1.31+20161214.1.c7d42e4+selfpack1-3ubuntu0.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-21408","CVE-2021-29454","CVE-2021-26120","CVE-2018-13982","CVE-2021-26119","CVE-2018-16831"]}]}],"offset":51640,"limit":20,"total_results":79316}