{"cves":[{"id":"CVE-2018-1000558","published":"2018-06-26T16:29:00","updated_at":"2025-08-26T12:02:56.222001+00:00","description":"\nOCS Inventory NG ocsreports 2.4 and ocsreports 2.3.1 version 2.4 and 2.3.1\ncontains a SQL Injection vulnerability in web search that can result in An\nauthenticated attacker is able to gain full access to data stored within\ndatabase. This attack appear to be exploitable via By sending crafted\nrequests it is possible to gain database access. This vulnerability appears\nto have been fixed in 2.4.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-1000558"],"bugs":[""],"patches":{"ocsinventory-server":[]},"tags":{},"packages":[{"name":"ocsinventory-server","source":"https://ubuntu.com/security/cve?package=ocsinventory-server","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ocsinventory-server","debian":"https://tracker.debian.org/pkg/ocsinventory-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.5+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-1000557","published":"2018-06-26T16:29:00","updated_at":"2025-08-26T12:02:56.222001+00:00","description":"\nOCS Inventory OCS Inventory NG version ocsreports 2.4 contains a Cross Site\nScripting (XSS) vulnerability in login form and search functionality that\ncan result in An attacker is able to execute arbitrary (javascript) code\nwithin a victims' browser. This attack appear to be exploitable via Victim\nmust open a crafted link to the application. This vulnerability appears to\nhave been fixed in ocsreports 2.4.1.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"Authentication is needed, only supported in trusted\nenvironments, see debtags"}],"codename":null,"priority":"negligible","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2018-1000557"],"bugs":[""],"patches":{"ocsinventory-server":[]},"tags":{},"packages":[{"name":"ocsinventory-server","source":"https://ubuntu.com/security/cve?package=ocsinventory-server","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ocsinventory-server","debian":"https://tracker.debian.org/pkg/ocsinventory-server","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.5+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.4.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-1000556","published":"2018-06-26T16:29:00","updated_at":"2025-07-11T07:39:09.739671+00:00","description":"\nWordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability\nin plugins.php or core wordpress on delete function that can result in An\nattacker can perform client side attacks which could be from stealing a\ncookie to code injection. This attack appear to be exploitable via an\nattacker must craft an URL with payload and send to the user. Victim need\nto open the link to be affected by reflected XSS. .","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.pluginvulnerabilities.com/2017/04/28/reflected-cross-site-scripting-xss-vulnerability-in-wp-statistics/","https://www.cve.org/CVERecord?id=CVE-2018-1000556"],"bugs":[""],"patches":{"wordpress":[]},"tags":{},"packages":[{"name":"wordpress","source":"https://ubuntu.com/security/cve?package=wordpress","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=wordpress","debian":"https://tracker.debian.org/pkg/wordpress","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-1000548","published":"2018-06-26T16:29:00","updated_at":"2025-08-26T12:02:56.222001+00:00","description":"\nUmlet version < 14.3 contains a XML External Entity (XXE) vulnerability in\nFile parsing that can result in disclosure of confidential data, denial of\nservice, server side request forgery. This attack appear to be exploitable\nvia Specially crafted UXF file. This vulnerability appears to have been\nfixed in 14.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://0dd.zone/2018/04/23/UMLet-XXE/","https://github.com/umlet/umlet/issues/500","https://www.cve.org/CVERecord?id=CVE-2018-1000548"],"bugs":[""],"patches":{"umlet":[]},"tags":{},"packages":[{"name":"umlet","source":"https://ubuntu.com/security/cve?package=umlet","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=umlet","debian":"https://tracker.debian.org/pkg/umlet","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"released","description":"15.1+ds-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"released","description":"15.1+ds-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"15.1+ds-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-1000546","published":"2018-06-26T16:29:00","updated_at":"2025-07-11T07:39:09.739671+00:00","description":"\nTriplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE)\nvulnerability in Importing game data that can result in Possible\ninformation disclosure, server-side request forgery, or remote code\nexecution. This attack appear to be exploitable via Specially crafted game\ndata file (XML).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://0dd.zone/2018/05/31/TripleA-XXE/","https://github.com/triplea-game/triplea/issues/3442","https://www.cve.org/CVERecord?id=CVE-2018-1000546"],"bugs":[""],"patches":{"triplea":[]},"tags":{},"packages":[{"name":"triplea","source":"https://ubuntu.com/security/cve?package=triplea","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=triplea","debian":"https://tracker.debian.org/pkg/triplea","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-1000544","published":"2018-06-26T16:29:00","updated_at":"2025-08-26T12:02:56.222001+00:00","description":"\nrubyzip gem rubyzip version 1.2.1 and earlier contains a Directory\nTraversal vulnerability in Zip::File component that can result in write\narbitrary files to the filesystem. This attack appear to be exploitable via\nIf a site allows uploading of .zip files , an attacker can upload a\nmalicious file that contains symlinks or files with absolute pathnames\n\"../\" to write arbitrary files to the filesystem..","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/rubyzip/rubyzip/issues/369","https://www.cve.org/CVERecord?id=CVE-2018-1000544"],"bugs":[""],"patches":{"ruby-zip":[]},"tags":{},"packages":[{"name":"ruby-zip","source":"https://ubuntu.com/security/cve?package=ruby-zip","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-zip","debian":"https://tracker.debian.org/pkg/ruby-zip","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1.2.1-1.1~build0.18.04.1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.2.1-1.1, 1.1.6-1+deb8u2","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.2.1-1.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-1000539","published":"2018-06-26T16:29:00","updated_at":"2025-08-26T12:02:56.222001+00:00","description":"\nNov json-jwt version >= 0.5.0 && < 1.9.4 contains a CWE-347: Improper\nVerification of Cryptographic Signature vulnerability in Decryption of\nAES-GCM encrypted JSON Web Tokens that can result in Attacker can forge a\nauthentication tag. This attack appear to be exploitable via network\nconnectivity. This vulnerability appears to have been fixed in 1.9.4 and\nlater.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/nov/json-jwt/pull/62","https://github.com/nov/json-jwt/commit/3393f394f271c87bd42ec23c300727b4437d1638","https://www.cve.org/CVERecord?id=CVE-2018-1000539"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=902721"],"patches":{"ruby-json-jwt":[]},"tags":{},"packages":[{"name":"ruby-json-jwt","source":"https://ubuntu.com/security/cve?package=ruby-json-jwt","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ruby-json-jwt","debian":"https://tracker.debian.org/pkg/ruby-json-jwt","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.9.4-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.11.0-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-1000532","published":"2018-06-26T16:29:00","updated_at":"2025-08-26T12:02:56.222001+00:00","description":"\nbeep version 1.3 and up contains a External Control of File Name or Path\nvulnerability in --device option that can result in Local unprivileged user\ncan inhibit execution of arbitrary programs by other users, allowing DoS.\nThis attack appear to be exploitable via The system must allow local users\nto run beep.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":4.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/johnath/beep/issues/11#issuecomment-379514298","https://www.cve.org/CVERecord?id=CVE-2018-1000532"],"bugs":[""],"patches":{"beep":[]},"tags":{},"packages":[{"name":"beep","source":"https://ubuntu.com/security/cve?package=beep","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=beep","debian":"https://tracker.debian.org/pkg/beep","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"1.4.3-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-1000528","published":"2018-06-26T16:29:00","updated_at":"2025-08-26T12:02:56.222001+00:00","description":"\nGONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001\ncontains a Cross Site Scripting (XSS) vulnerability in change password form\n(html/password.php, #308) that can result in injection of arbitrary web\nscript or HTML. This attack appear to be exploitable via the victim must\nopen a specially crafted web page. This vulnerability appears to have been\nfixed in after commit 56070d6289d47ba3f5918885954dcceb75606001.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/gosa-project/gosa-core/commit/56070d6289d47ba3f5918885954dcceb75606001","https://github.com/gosa-project/gosa-core/issues/14","https://ubuntu.com/security/notices/USN-4609-1","https://www.cve.org/CVERecord?id=CVE-2018-1000528"],"bugs":[""],"patches":{"gosa":[]},"tags":{},"packages":[{"name":"gosa","source":"https://ubuntu.com/security/cve?package=gosa","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gosa","debian":"https://tracker.debian.org/pkg/gosa","statuses":[{"release_codename":"xenial","status":"released","description":"2.7.4+reloaded2-9ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.7.4+reloaded3-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-4609-1"],"notices":[{"id":"USN-4609-1","title":"GOsa vulnerabilities","summary":"Several security issues were fixed in gosa.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-10-28T19:46:46.393351","description":"Fabian Henneke discovered that GOsa incorrectly handled client cookies. An\nauthenticated user could exploit this with a crafted cookie to perform\nfile deletions in the context of the user account that runs the web\nserver. (CVE-2019-14466)\n\nIt was discovered that GOsa incorrectly handled user access control. A\nremote attacker could use this issue to log into any account with a\nusername containing the word \"success\". (CVE-2019-11187)\n\nFabian Henneke discovered that GOsa was vulnerable to cross-site scripting\nattacks via the change password form. A remote attacker could use this\nflaw to run arbitrary web scripts. (CVE-2018-1000528)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"gosa","version":"2.7.4+reloaded2-9ubuntu1.1","description":"Web Based LDAP Administration Program","is_source":true},{"name":"gosa","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-desktop","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-dev","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-help-de","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-help-en","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-help-fr","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-help-nl","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-connectivity","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-dhcp","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-dhcp-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-dns","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-dns-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-fai","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-fai-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-gofax","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-gofon","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-goto","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-kolab","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-kolab-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-ldapmanager","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-mail","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-mit-krb5","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-mit-krb5-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-nagios","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-nagios-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-netatalk","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-opengroupware","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-openxchange","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-openxchange-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-opsi","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-phpgw","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-phpgw-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-phpscheduleit","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-phpscheduleit-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-pptp","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-pptp-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-pureftpd","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-pureftpd-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-rolemanagement","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-rsyslog","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-samba","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-scalix","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-squid","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-ssh","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-ssh-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-sudo","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-sudo-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-systems","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-uw-imap","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-plugin-webdav","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"},{"name":"gosa-schema","version":"2.7.4+reloaded2-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/gosa","version_link":"https://launchpad.net/ubuntu/+source/gosa/2.7.4+reloaded2-9ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2019-11187","CVE-2018-1000528","CVE-2019-14466"]}]},{"id":"CVE-2018-1000520","published":"2018-06-26T16:29:00","updated_at":"2025-07-11T07:39:09.739671+00:00","description":"\nARM mbedTLS version 2.7.0 and earlier contains a Ciphersuite Allows\nIncorrectly Signed Certificates vulnerability in\nmbedtls_ssl_get_verify_result() that can result in ECDSA-signed\ncertificates are accepted, when only RSA-signed ones should be.. This\nattack appear to be exploitable via Peers negotiate a TLS-ECDH-RSA-*\nciphersuite. Any of the peers can then provide an ECDSA-signed certificate,\nwhen only an RSA-signed one should be accepted..","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/ARMmbed/mbedtls/issues/1561","https://www.cve.org/CVERecord?id=CVE-2018-1000520"],"bugs":[""],"patches":{"mbedtls":[]},"tags":{},"packages":[{"name":"mbedtls","source":"https://ubuntu.com/security/cve?package=mbedtls","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mbedtls","debian":"https://tracker.debian.org/pkg/mbedtls","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"noble","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"plucky","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"oracular","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-1000500","published":"2018-06-26T16:29:00","updated_at":"2025-08-25T22:42:58.430259+00:00","description":"\nBusybox contains a Missing SSL certificate validation vulnerability in The\n\"busybox wget\" applet that can result in arbitrary code execution. This\nattack appear to be exploitable via Simply download any file over HTTPS\nusing \"busybox wget https://compromised-domain.com/important-file\".","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"per Red Hat, SSL support was added in 1.23.0. Older versions\ndon't support https at all."}],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://lists.busybox.net/pipermail/busybox/2018-May/086462.html","https://git.busybox.net/busybox/tree/networking/wget.c?id=8bc418f07eab79a9c8d26594629799f6157a9466#n74","https://ubuntu.com/security/notices/USN-4531-1","https://www.cve.org/CVERecord?id=CVE-2018-1000500"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/busybox/+bug/1879533"],"patches":{"busybox":["upstream: https://git.busybox.net/busybox/commit/?id=0972c7f7a570c38edb68e1c60a45614b7a7c7d55","upstream: https://git.busybox.net/busybox/commit/?id=dbe95682b4bf1192d2860646617f157e6c44f2d1","upstream: https://git.busybox.net/busybox/commit/?id=45fa3f18adf57ef9d743038743d9c90573aeeb91"]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:1.27.2-2ubuntu3.3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.30.1-4ubuntu6.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-4531-1"],"notices":[{"id":"USN-4531-1","title":"BusyBox vulnerability","summary":"Fraudulent security certificates could allow sensitive information to\nbe exposed when accessing the Internet.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2020-09-22T13:57:23.605010","description":"It was discovered that the BusyBox wget applet incorrectly validated SSL\ncertificates. A remote attacker could possibly use this issue to intercept\nsecure communications.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"busybox","version":"1:1.27.2-2ubuntu3.3","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.3","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.3","pocket":"security"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu3.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.3","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.3","pocket":"security"},{"name":"busybox-udeb","version":"1:1.27.2-2ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.3","pocket":"security"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.3","pocket":"security"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu3.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.3","pocket":"security"}],"focal":[{"name":"busybox","version":"1:1.30.1-4ubuntu6.2","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.30.1-4ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.2","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.30.1-4ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.2","pocket":"security"},{"name":"busybox-static","version":"1:1.30.1-4ubuntu6.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.2","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.30.1-4ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.2","pocket":"security"},{"name":"busybox-udeb","version":"1:1.30.1-4ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.2","pocket":"security"},{"name":"udhcpc","version":"1:1.30.1-4ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.2","pocket":"security"},{"name":"udhcpd","version":"1:1.30.1-4ubuntu6.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.30.1-4ubuntu6.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-1000500"]}]},{"id":"CVE-2018-1000205","published":"2018-06-26T16:29:00","updated_at":"2025-08-26T12:02:56.222001+00:00","description":"\nU-Boot contains a CWE-20: Improper Input Validation vulnerability in\nVerified boot signature validation that can result in Bypass verified boot.\nThis attack appear to be exploitable via Specially crafted FIT image and\nspecial device memory functionality.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"verified boot not used in Ubuntu, setting as \"negligible\""}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://lists.denx.de/pipermail/u-boot/2018-June/330454.html","https://lists.denx.de/pipermail/u-boot/2018-June/330898.html","https://www.cve.org/CVERecord?id=CVE-2018-1000205"],"bugs":[""],"patches":{"u-boot":["upstream: https://github.com/u-boot/u-boot/commit/72239fc85f3eda078547956608c063ab965e90e9","upstream: https://github.com/u-boot/u-boot/commit/7346c1e192d63cd35f99c7e845e53c5d4d0bdc24","other: https://lists.denx.de/pipermail/u-boot/2018-June/330488.html"]},"tags":{},"packages":[{"name":"u-boot","source":"https://ubuntu.com/security/cve?package=u-boot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=u-boot","debian":"https://tracker.debian.org/pkg/u-boot","statuses":[{"release_codename":"impish","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2019.07+dfsg-1ubuntu4~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2019.07+dfsg-1ubuntu6","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2020.04+dfsg-2ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7657","published":"2018-06-26T16:29:00","updated_at":"2025-08-26T12:01:36.252587+00:00","description":"\nIn Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and\n9.4.x (non-default configuration with RFC2616 compliance enabled),\ntransfer-encoding chunks are handled poorly. The chunk length parsing was\nvulnerable to an integer overflow. Thus a large chunk size could be\ninterpreted as a smaller chunk size and content sent as chunk body could be\ninterpreted as a pipelined request. If Jetty was deployed behind an\nintermediary that imposed some authorization and that intermediary allowed\narbitrarily large chunks to be passed on unchanged, then this flaw could be\nused to bypass the authorization imposed by the intermediary as the fake\npipelined request would not be interpreted by the intermediary as a\nrequest.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"jetty8 ignored (very hard to exploit, complex patch)"}],"codename":null,"priority":"low","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://bugs.eclipse.org/bugs/show_bug.cgi?id=535668","https://www.cve.org/CVERecord?id=CVE-2017-7657"],"bugs":[""],"patches":{"jetty8":[],"jetty9":[]},"tags":{},"packages":[{"name":"jetty9","source":"https://ubuntu.com/security/cve?package=jetty9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jetty9","debian":"https://tracker.debian.org/pkg/jetty9","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2.25-1, 9.2.21-1+deb9u1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"}]},{"name":"jetty8","source":"https://ubuntu.com/security/cve?package=jetty8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jetty8","debian":"https://tracker.debian.org/pkg/jetty8","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7656","published":"2018-06-26T15:29:00","updated_at":"2025-08-26T12:01:36.252587+00:00","description":"\nIn Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and\n9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9\nis handled poorly. An HTTP/1 style request line (i.e. method space URI\nspace version) that declares a version of HTTP/0.9 was accepted and treated\nas a 0.9 request. If deployed behind an intermediary that also accepted and\npassed through the 0.9 version (but did not act on it), then the response\nsent could be interpreted by the intermediary as HTTP/1 headers. This could\nbe used to poison the cache if the server allowed the origin client to\ngenerate arbitrary content in the response.","ubuntu_description":"","notes":[{"author":"ebarretto","note":"jetty8 ignored (very hard to exploit, complex patch)"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://bugs.eclipse.org/bugs/show_bug.cgi?id=535667","https://www.cve.org/CVERecord?id=CVE-2017-7656"],"bugs":[""],"patches":{"jetty8":[],"jetty9":[]},"tags":{},"packages":[{"name":"jetty9","source":"https://ubuntu.com/security/cve?package=jetty9","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jetty9","debian":"https://tracker.debian.org/pkg/jetty9","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2.25-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"9.2.26-1","component":null,"pocket":"security"}]},{"name":"jetty8","source":"https://ubuntu.com/security/cve?package=jetty8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jetty8","debian":"https://tracker.debian.org/pkg/jetty8","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"9.2.25-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-10852","published":"2018-06-26T14:29:00","updated_at":"2025-08-18T17:07:33.457807+00:00","description":"\nThe UNIX pipe which sudo uses to contact SSSD and read the available sudo\nrules from SSSD has too wide permissions, which means that anyone who can\nsend a message using the same raw protocol that sudo and SSSD use can read\nthe sudo rules available for any user. This affects versions of SSSD before\n1.16.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":3.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.8,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://lists.fedoraproject.org/archives/list/sssd-users@lists.fedorahosted.org/message/XUCDLKDVH7HZKPSJ7GEJAVNZS5CW35EK/","https://ubuntu.com/security/notices/USN-5067-1","https://www.cve.org/CVERecord?id=CVE-2018-10852"],"bugs":["https://pagure.io/SSSD/sssd/issue/3766","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=902860"],"patches":{"sssd":["upstream: https://pagure.io/SSSD/sssd/c/ed90a20a0f0e936eb00d268080716c0384ffb01d"]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"bionic","status":"released","description":"1.16.1-1ubuntu1.8","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.2.0-4ubuntu1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.16.3-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"2.2.2-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-5067-1"],"notices":[{"id":"USN-5067-1","title":"SSSD vulnerabilities","summary":"Several security issues were fixed in sssd.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-09-08T11:40:23.694368","description":"Jakub Hrozek discovered that SSSD incorrectly handled file permissions. A\nlocal attacker could possibly use this issue to read the sudo rules\navailable for any user. This issue only affected Ubuntu 18.04 LTS.\n(CVE-2018-10852)\n\nIt was discovered that SSSD incorrectly handled Group Policy Objects. When\nSSSD is configured with too strict permissions causing the GPO to not be\nreadable, SSSD will allow all authenticated users to login instead of being\ndenied, contrary to expectations. This issue only affected Ubuntu 18.04\nLTS. (CVE-2018-16838)\n\nIt was discovered that SSSD incorrectly handled users with no home\ndirectory set. When no home directory was set, SSSD would return the root\ndirectory instead of an empty string, possibly bypassing security measures.\nThis issue only affected Ubuntu 18.04 LTS. (CVE-2019-3811)\n\nCedric Buissart discovered that SSSD incorrectly handled the sssctl\ncommand. In certain environments, a local user could use this issue to\nexecute arbitrary commands and possibly escalate privileges.\n(CVE-2021-3621)\n","is_hidden":false,"release_packages":{"hirsute":[{"name":"sssd","version":"2.4.0-1ubuntu6.1","description":"System Security Services Daemon","is_source":true},{"name":"libsss-certmap-dev","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libipa-hbac-dev","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-ad","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libsss-sudo","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libsss-nss-idmap0","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libnss-sss","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-ipa","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libsss-simpleifp0","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libsss-idmap-dev","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"python3-libsss-nss-idmap","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libsss-certmap0","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"python3-sss","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libpam-sss","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libsss-idmap0","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libipa-hbac0","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libsss-nss-idmap-dev","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libsss-simpleifp-dev","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-kcm","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libwbclient-sssd","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"libwbclient-sssd-dev","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-common","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"python3-libipa-hbac","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-ldap","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-tools","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-ad-common","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-krb5-common","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-dbus","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-krb5","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"},{"name":"sssd-proxy","version":"2.4.0-1ubuntu6.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.4.0-1ubuntu6.1","pocket":"security"}],"focal":[{"name":"sssd","version":"2.2.3-3ubuntu0.7","description":"System Security Services Daemon","is_source":true},{"name":"libsss-certmap-dev","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libipa-hbac-dev","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-ad","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libsss-sudo","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libsss-nss-idmap0","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libnss-sss","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-ipa","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libsss-simpleifp0","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libsss-idmap-dev","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"python3-libsss-nss-idmap","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libsss-certmap0","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"python3-sss","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libpam-sss","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libsss-idmap0","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libipa-hbac0","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libsss-nss-idmap-dev","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libsss-simpleifp-dev","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-kcm","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libwbclient-sssd","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"libwbclient-sssd-dev","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-common","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"python3-libipa-hbac","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-ldap","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-tools","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-ad-common","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-krb5-common","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-dbus","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-krb5","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"},{"name":"sssd-proxy","version":"2.2.3-3ubuntu0.7","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/2.2.3-3ubuntu0.7","pocket":"security"}],"bionic":[{"name":"sssd","version":"1.16.1-1ubuntu1.8","description":"System Security Services Daemon","is_source":true},{"name":"libsss-certmap-dev","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libipa-hbac-dev","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-ad","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libsss-sudo","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libsss-nss-idmap0","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libnss-sss","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-ipa","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libsss-simpleifp0","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libsss-idmap-dev","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"python3-libsss-nss-idmap","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libsss-certmap0","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"python3-sss","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libpam-sss","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"python-libsss-nss-idmap","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libsss-idmap0","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-ldap","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libsss-nss-idmap-dev","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libsss-simpleifp-dev","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-kcm","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"python-libipa-hbac","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libwbclient-sssd","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libwbclient-sssd-dev","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-common","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"python3-libipa-hbac","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"libipa-hbac0","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-tools","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-ad-common","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-krb5-common","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-dbus","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-krb5","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"python-sss","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"},{"name":"sssd-proxy","version":"1.16.1-1ubuntu1.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/sssd","version_link":"https://launchpad.net/ubuntu/+source/sssd/1.16.1-1ubuntu1.8","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2021-3621","CVE-2018-10852","CVE-2019-3811","CVE-2018-16838"]}]},{"id":"CVE-2018-0608","published":"2018-06-26T14:29:00","updated_at":"2025-08-26T12:02:40.614240+00:00","description":"\nBuffer overflow in H2O version 2.2.4 and earlier allows remote attackers to\nexecute arbitrary code or cause a denial of service (DoS) via unspecified\nvectors.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/h2o/h2o/issues/1775","https://www.cve.org/CVERecord?id=CVE-2018-0608"],"bugs":[""],"patches":{"h2o":[]},"tags":{},"packages":[{"name":"h2o","source":"https://ubuntu.com/security/cve?package=h2o","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=h2o","debian":"https://tracker.debian.org/pkg/h2o","statuses":[{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.2.5+dfsg2-3build1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.2.5+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2018-12900","published":"2018-06-26T00:00:00","updated_at":"2025-08-25T22:46:35.615285+00:00","description":"\nHeap-based buffer overflow in the cpSeparateBufToContigBuf function in\ntiffcp.c in LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0beta7,\n4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4,\n4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 allows remote attackers to\ncause a denial of service (crash) or possibly have unspecified other impact\nvia a crafted TIFF file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"issue is in tiffcp utility"}],"codename":null,"priority":"low","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3906-1","https://ubuntu.com/security/notices/USN-3906-2","https://www.cve.org/CVERecord?id=CVE-2018-12900"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2798","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=902718"],"patches":{"tiff":["other: https://gitlab.com/libtiff/libtiff/merge_requests/44","other: https://gitlab.com/libtiff/libtiff/merge_requests/60","upstream: https://gitlab.com/libtiff/libtiff/commit/27124e9148b2056d0e0bf4033b4924d5d2a38d01"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.0.9-5ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"4.0.9-6ubuntu0.2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.11","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.10-4","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.6","component":null,"pocket":"security"}]}],"notices_ids":["USN-3906-2","USN-3906-1"],"notices":[{"id":"USN-3906-2","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-03-18T13:57:47.692667","description":"USN-3906-1 and USN-3864-1 fixed several vulnerabilities in LibTIFF. This update\nprovides the corresponding update for Ubuntu 12.04 ESM.\n\nOriginal advisory details:\n\n It was discovered that LibTIFF incorrectly handled certain malformed\n images. If a user or automated system were tricked into opening a specially\n crafted image, a remote attacker could crash the application, leading to a\n denial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"precise":[{"name":"tiff","version":"3.9.5-2ubuntu1.12","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff4","version":"3.9.5-2ubuntu1.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.12"},{"name":"libtiff-tools","version":"3.9.5-2ubuntu1.12","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/3.9.5-2ubuntu1.12"}]},"type":"USN","cves_ids":["CVE-2018-10779","CVE-2018-12900","CVE-2018-17100","CVE-2018-17101","CVE-2018-18557","CVE-2019-6128","CVE-2019-7663"]},{"id":"USN-3906-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-03-12T13:08:54.152837","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"bionic":[{"name":"tiff","version":"4.0.9-5ubuntu0.2","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-dev","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff-doc","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff-tools","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff5","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"},{"name":"libtiffxx5","version":"4.0.9-5ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-5ubuntu0.2","pocket":"security"}],"cosmic":[{"name":"tiff","version":"4.0.9-6ubuntu0.2","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-dev","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff-doc","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff-opengl","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff-tools","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff5","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiff5-dev","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"},{"name":"libtiffxx5","version":"4.0.9-6ubuntu0.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.9-6ubuntu0.2"}],"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.11","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.11","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.6","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.6","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-10779","CVE-2018-12900","CVE-2018-17000","CVE-2018-19210","CVE-2019-6128","CVE-2019-7663"]}]},{"id":"CVE-2018-1000517","published":"2018-06-26T00:00:00","updated_at":"2025-08-25T22:42:58.430259+00:00","description":"\nBusyBox project BusyBox wget version prior to commit\n8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e contains a Buffer Overflow\nvulnerability in Busybox wget that can result in heap buffer overflow. This\nattack appear to be exploitable via network connectivity. This\nvulnerability appears to have been fixed in after commit\n8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3935-1","https://www.cve.org/CVERecord?id=CVE-2018-1000517"],"bugs":["https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=902724"],"patches":{"busybox":["upstream: https://git.busybox.net/busybox/commit/?id=8e2174e9bd836e53c8b9c6e00d1bc6e2a718686e"]},"tags":{},"packages":[{"name":"busybox","source":"https://ubuntu.com/security/cve?package=busybox","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=busybox","debian":"https://tracker.debian.org/pkg/busybox","statuses":[{"release_codename":"hirsute","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"1:1.27.2-2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"1:1.27.2-2ubuntu4.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"eoan","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"focal","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"groovy","status":"released","description":"1:1.27.2-2ubuntu5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:1.21.0-1ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.27.2-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:1.22.0-15ubuntu1.4","component":null,"pocket":"security"}]}],"notices_ids":["USN-3935-1"],"notices":[{"id":"USN-3935-1","title":"BusyBox vulnerabilities","summary":"Several security issues were fixed in BusyBox.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-04-03T11:59:48.636617","description":"Tyler Hicks discovered that BusyBox incorrectly handled symlinks inside tar\narchives. If a user or automated system were tricked into processing a\nspecially crafted tar archive, a remote attacker could overwrite arbitrary\nfiles outside of the current directory. This issue only affected Ubuntu\n14.04 LTS and Ubuntu 16.04 LTS. (CVE-2011-5325)\n\nMathias Krause discovered that BusyBox incorrectly handled kernel module\nloading restrictions. A local attacker could possibly use this issue to\nbypass intended restrictions. This issue only affected Ubuntu 14.04 LTS.\n(CVE-2014-9645)\n\nIt was discovered that BusyBox incorrectly handled certain ZIP archives. If\na user or automated system were tricked into processing a specially crafted\nZIP archive, a remote attacker could cause BusyBox to crash, leading to a\ndenial of service. This issue only affected Ubuntu 14.04 LTS and Ubuntu\n16.04 LTS. (CVE-2015-9261)\n\nNico Golde discovered that the BusyBox DHCP client incorrectly handled\ncertain malformed domain names. A remote attacker could possibly use this\nissue to cause the DHCP client to crash, leading to a denial of service.\nThis issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.\n(CVE-2016-2147)\n\nNico Golde discovered that the BusyBox DHCP client incorrectly handled\ncertain 6RD options. A remote attacker could use this issue to cause the\nDHCP client to crash, leading to a denial of service, or possibly execute\narbitrary code. This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04\nLTS. (CVE-2016-2148)\n\nIt was discovered that BusyBox incorrectly handled certain bzip2 archives.\nIf a user or automated system were tricked into processing a specially\ncrafted bzip2 archive, a remote attacker could cause BusyBox to crash,\nleading to a denial of service, or possibly execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-15873)\n\nIt was discovered that BusyBox incorrectly handled tab completion. A local\nattacker could possibly use this issue to execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2017-16544)\n\nIt was discovered that the BusyBox wget utility incorrectly handled certain\nresponses. A remote attacker could use this issue to cause BusyBox to\ncrash, resulting in a denial of service, or possibly execute arbitrary\ncode. (CVE-2018-1000517)\n\nIt was discovered that the BusyBox DHCP utilities incorrectly handled\ncertain memory operations. A remote attacker could possibly use this issue\nto access sensitive information. (CVE-2018-20679, CVE-2019-5747)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"busybox","version":"1:1.27.2-2ubuntu3.2","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"busybox-udeb","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu3.2","pocket":"security"}],"cosmic":[{"name":"busybox","version":"1:1.27.2-2ubuntu4.1","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-initramfs","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-static","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-syslogd","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"busybox-udeb","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"udhcpc","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"},{"name":"udhcpd","version":"1:1.27.2-2ubuntu4.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.27.2-2ubuntu4.1"}],"trusty":[{"name":"busybox","version":"1:1.21.0-1ubuntu1.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-static","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"busybox-udeb","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"udhcpc","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"},{"name":"udhcpd","version":"1:1.21.0-1ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.21.0-1ubuntu1.4","pocket":"security"}],"xenial":[{"name":"busybox","version":"1:1.22.0-15ubuntu1.4","description":"Tiny utilities for small and embedded systems","is_source":true},{"name":"busybox","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-initramfs","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-static","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-syslogd","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"busybox-udeb","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"udhcpc","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"},{"name":"udhcpd","version":"1:1.22.0-15ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/busybox","version_link":"https://launchpad.net/ubuntu/+source/busybox/1:1.22.0-15ubuntu1.4","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2011-5325","CVE-2014-9645","CVE-2015-9261","CVE-2016-2147","CVE-2016-2148","CVE-2017-15873","CVE-2017-16544","CVE-2018-1000517","CVE-2018-20679","CVE-2019-5747"]}]},{"id":"CVE-2018-1000204","published":"2018-06-26T00:00:00","updated_at":"2026-07-04T07:43:48.105124+00:00","description":"\nLinux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on\n/dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp.\nThis may lead to copying up to 1000 kernel heap pages to the userspace.\nThis has been fixed upstream in\nhttps://github.com/torvalds/linux/commit/a45b599ad808c3c982fdcdc12b0b8611c2f92824\nalready. The problem has limited scope, as users don't usually have\npermissions to access SCSI devices. On the other hand, e.g. the Nero user\nmanual suggests doing `chmod o+r+w /dev/sg*` to make the devices\naccessible. NOTE: third parties dispute the relevance of this report,\nnoting that the requirement for an attacker to have both the CAP_SYS_ADMIN\nand CAP_SYS_RAWIO capabilities makes it \"virtually impossible to exploit.","ubuntu_description":"\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory).","notes":[],"codename":null,"priority":"negligible","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=a45b599ad808c3c982fdcdc12b0b8611c2f92824","https://ubuntu.com/security/notices/USN-3696-1","https://ubuntu.com/security/notices/USN-3696-2","https://ubuntu.com/security/notices/USN-3752-1","https://ubuntu.com/security/notices/USN-3752-2","https://ubuntu.com/security/notices/USN-3754-1","https://ubuntu.com/security/notices/USN-3752-3","https://www.cve.org/CVERecord?id=CVE-2018-1000204"],"bugs":[""],"patches":{"linux":["break-fix: - a45b599ad808c3c982fdcdc12b0b8611c2f92824"],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-azure-edge":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-hwe-5.4":[],"linux-hwe-5.15":[],"linux-hwe-6.8":[],"linux-aws-5.4":[],"linux-aws-5.15":[],"linux-aws-hwe":[],"linux-azure-4.15":[],"linux-azure-5.4":[],"linux-azure-5.15":[],"linux-azure-fde":[],"linux-azure-fde-5.15":[],"linux-bluefield":[],"linux-fips":[],"linux-aws-fips":[],"linux-azure-fips":[],"linux-gcp-fips":[],"linux-gcp-4.15":[],"linux-gcp-5.4":[],"linux-gcp-5.15":[],"linux-gkeop":[],"linux-gkeop-5.15":[],"linux-ibm":[],"linux-ibm-5.4":[],"linux-ibm-5.15":[],"linux-intel":[],"linux-intel-iotg":[],"linux-intel-iotg-5.15":[],"linux-iot":[],"linux-intel-iot-realtime":[],"linux-lowlatency":[],"linux-lowlatency-hwe-5.15":[],"linux-lowlatency-hwe-6.8":[],"linux-nvidia":[],"linux-nvidia-6.5":[],"linux-nvidia-6.8":[],"linux-nvidia-lowlatency":[],"linux-oracle":[],"linux-oracle-5.4":[],"linux-oracle-5.15":[],"linux-oem-6.8":[],"linux-raspi":[],"linux-raspi-5.4":[],"linux-raspi-realtime":[],"linux-realtime":[],"linux-riscv":[],"linux-riscv-5.15":[],"linux-riscv-6.8":[],"linux-xilinx-zynqmp":[],"linux-aws-6.8":[],"linux-gcp-6.8":[],"linux-oracle-6.8":[],"linux-azure-6.8":[],"linux-oem-6.11":[],"linux-hwe-6.11":[],"linux-hwe-6.14":[],"linux-aws-6.14":[],"linux-azure-6.11":[],"linux-azure-nvidia":[],"linux-gcp-6.11":[],"linux-gcp-6.14":[],"linux-ibm-6.8":[],"linux-lowlatency-hwe-6.11":[],"linux-nvidia-tegra":[],"linux-nvidia-tegra-5.15":[],"linux-nvidia-tegra-igx":[],"linux-oracle-6.14":[],"linux-oem-6.14":[],"linux-riscv-6.14":[],"linux-nvidia-6.11":[],"linux-realtime-6.8":[],"linux-realtime-6.14":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"]},"packages":[{"name":"linux-aws-fips","source":"https://ubuntu.com/security/cve?package=linux-aws-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-fips","debian":"https://tracker.debian.org/pkg/linux-aws-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1052.57+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-2000.4","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips2","component":null,"pocket":"fips"}]},{"name":"linux-azure-fips","source":"https://ubuntu.com/security/cve?package=linux-azure-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-fips","debian":"https://tracker.debian.org/pkg/linux-azure-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1058.66+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1022.22+fips1","component":null,"pocket":"fips"}]},{"name":"linux-gcp-fips","source":"https://ubuntu.com/security/cve?package=linux-gcp-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-fips","debian":"https://tracker.debian.org/pkg/linux-gcp-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1048.56+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips1","component":null,"pocket":"fips"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"fips"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.15.0-33.36","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.17.0-6.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-157.207","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-130.156","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-10.11","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-9.12","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-19.19","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.15.0-1020.20","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1020.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-1024.25","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1062.71","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1002.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1008.8","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1008.8","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-aws-5.15","source":"https://ubuntu.com/security/cve?package=linux-aws-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.15","debian":"https://tracker.debian.org/pkg/linux-aws-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.19~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-5.4","source":"https://ubuntu.com/security/cve?package=linux-aws-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.4","debian":"https://tracker.debian.org/pkg/linux-aws-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1020.20~18.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-6.14","source":"https://ubuntu.com/security/cve?package=linux-aws-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.14","debian":"https://tracker.debian.org/pkg/linux-aws-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-aws-6.8","source":"https://ubuntu.com/security/cve?package=linux-aws-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.8","debian":"https://tracker.debian.org/pkg/linux-aws-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1009.9~22.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1031.33~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1022.23","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.18.0-1003.3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1022.22~16.04.1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1003.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1006.6","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1006.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1082.92","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.8~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1022.22~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-6.11","source":"https://ubuntu.com/security/cve?package=linux-azure-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.11","debian":"https://tracker.debian.org/pkg/linux-azure-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-azure-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-azure-6.8","source":"https://ubuntu.com/security/cve?package=linux-azure-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.8","debian":"https://tracker.debian.org/pkg/linux-azure-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"bionic","status":"not-affected","description":"4.18.0-1003.3~18.04.1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde","source":"https://ubuntu.com/security/cve?package=linux-azure-fde","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde","debian":"https://tracker.debian.org/pkg/linux-azure-fde","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1019.24.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.14.0-1012.12","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1041.48","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-azure-fde-5.15]","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-fde-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]},{"name":"linux-azure-nvidia","source":"https://ubuntu.com/security/cve?package=linux-azure-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-nvidia","debian":"https://tracker.debian.org/pkg/linux-azure-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1013.14","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-bluefield","source":"https://ubuntu.com/security/cve?package=linux-bluefield","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-bluefield","debian":"https://tracker.debian.org/pkg/linux-bluefield","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1011.14","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-fips","source":"https://ubuntu.com/security/cve?package=linux-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fips","debian":"https://tracker.debian.org/pkg/linux-fips","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-92.102+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1017.22~recert1","component":null,"pocket":"fips"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1011.12","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.8","component":null,"pocket":"fips"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"bionic","status":"released","description":"4.15.0-1018.19","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1018.19","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-1018.19~16.04.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1002.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1003.3","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1071.81","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.15","debian":"https://tracker.debian.org/pkg/linux-gcp-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1006.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.4","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.4","debian":"https://tracker.debian.org/pkg/linux-gcp-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.11","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.11","debian":"https://tracker.debian.org/pkg/linux-gcp-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-gcp-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.14","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.14","debian":"https://tracker.debian.org/pkg/linux-gcp-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.8","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.8","debian":"https://tracker.debian.org/pkg/linux-gcp-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1010.11~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop","source":"https://ubuntu.com/security/cve?package=linux-gkeop","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gkeop","debian":"https://tracker.debian.org/pkg/linux-gkeop","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1008.9","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop-5.15","source":"https://ubuntu.com/security/cve?package=linux-gkeop-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gkeop-5.15","debian":"https://tracker.debian.org/pkg/linux-gkeop-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-33.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-37.41~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.14","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.14","debian":"https://tracker.debian.org/pkg/linux-hwe-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-24.24~24.04.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.15.0-33.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.0.0-15.16~18.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm","source":"https://ubuntu.com/security/cve?package=linux-ibm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm","debian":"https://tracker.debian.org/pkg/linux-ibm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1009.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.15","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.15","debian":"https://tracker.debian.org/pkg/linux-ibm-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1034.37~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.4","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.4","debian":"https://tracker.debian.org/pkg/linux-ibm-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1010.11~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-6.8","source":"https://ubuntu.com/security/cve?package=linux-ibm-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm-6.8","debian":"https://tracker.debian.org/pkg/linux-ibm-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-intel","source":"https://ubuntu.com/security/cve?package=linux-intel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel","debian":"https://tracker.debian.org/pkg/linux-intel","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iot-realtime","source":"https://ubuntu.com/security/cve?package=linux-intel-iot-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel-iot-realtime","debian":"https://tracker.debian.org/pkg/linux-intel-iot-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1021.26","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg","debian":"https://tracker.debian.org/pkg/linux-intel-iotg","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1004.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg-5.15","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg-5.15","debian":"https://tracker.debian.org/pkg/linux-intel-iotg-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-iot","source":"https://ubuntu.com/security/cve?package=linux-iot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-iot","debian":"https://tracker.debian.org/pkg/linux-iot","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.15.0-1020.20","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1020.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1029.34","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1003.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency","debian":"https://tracker.debian.org/pkg/linux-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-22.22","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"replaced by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-130.156~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-nvidia","source":"https://ubuntu.com/security/cve?package=linux-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia","debian":"https://tracker.debian.org/pkg/linux-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1005.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.11","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.11","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1002.2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.5","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.5","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.5.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.8","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.8","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-nvidia-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-lowlatency","debian":"https://tracker.debian.org/pkg/linux-nvidia-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1009.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1013.13","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-5.15","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-5.15","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1009.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-igx","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-igx","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-igx","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-igx","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.15.0-1017.20","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1017.20","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1021.24","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.11","source":"https://ubuntu.com/security/cve?package=linux-oem-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.11","debian":"https://tracker.debian.org/pkg/linux-oem-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.14","source":"https://ubuntu.com/security/cve?package=linux-oem-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.14","debian":"https://tracker.debian.org/pkg/linux-oem-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1005.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-oem-6.8","source":"https://ubuntu.com/security/cve?package=linux-oem-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.8","debian":"https://tracker.debian.org/pkg/linux-oem-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1010.10","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1008.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1008.10~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1005.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1006.6","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.15","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.15","debian":"https://tracker.debian.org/pkg/linux-oracle-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.4","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.4","debian":"https://tracker.debian.org/pkg/linux-oracle-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.14","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.14","debian":"https://tracker.debian.org/pkg/linux-oracle-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.8","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.8","debian":"https://tracker.debian.org/pkg/linux-oracle-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1006.6~22.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1005.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1004.4","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1013.13~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi-realtime","source":"https://ubuntu.com/security/cve?package=linux-raspi-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi-realtime","debian":"https://tracker.debian.org/pkg/linux-raspi-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.7.0-2001.1","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"4.15.0-1021.23","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1021.23","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1092.100","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.18.0-1005.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [replaced by linux-raspi]","component":null,"pocket":"security"}]},{"name":"linux-realtime","source":"https://ubuntu.com/security/cve?package=linux-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-realtime","debian":"https://tracker.debian.org/pkg/linux-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1006.6","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.1-1015.16","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.14","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.14","debian":"https://tracker.debian.org/pkg/linux-realtime-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1003.3~24.04.3","component":null,"pocket":"realtime"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.8","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.8","debian":"https://tracker.debian.org/pkg/linux-realtime-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.1-1004.4~22.04.1","component":null,"pocket":"realtime"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-riscv-5.8]","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.15","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.15","debian":"https://tracker.debian.org/pkg/linux-riscv-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.17~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.14","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.14","debian":"https://tracker.debian.org/pkg/linux-riscv-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-22.22.1~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.8","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.8","debian":"https://tracker.debian.org/pkg/linux-riscv-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"artful","status":"released","description":"4.4.0-1095.100","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1095.100","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-xilinx-zynqmp","source":"https://ubuntu.com/security/cve?package=linux-xilinx-zynqmp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-xilinx-zynqmp","debian":"https://tracker.debian.org/pkg/linux-xilinx-zynqmp","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1020.24","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1022.26","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.17~rc7, 4.4.133","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3752-2","USN-3752-1","USN-3752-3","USN-3696-2","USN-3696-1","USN-3754-1"],"notices":[{"id":"USN-3752-2","title":"Linux kernel (HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-08-24T00:41:04.873085","description":"USN-3752-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu\n16.04 LTS.\n\nIt was discovered that, when attempting to handle an out-of-memory\nsituation, a null pointer dereference could be triggered in the Linux\nkernel in some circumstances. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2018-1000200)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly validate meta-data information. An attacker could\nuse this to construct a malicious xfs image that, when mounted, could cause\na denial of service (system crash). (CVE-2018-10323)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly validate xattr information. An attacker could use\nthis to construct a malicious xfs image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10840)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly keep meta-data information consistent in some\nsituations. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10881)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly handle corrupted meta data in some situations. An\nattacker could use this to specially craft an ext4 filesystem that caused a\ndenial of service (system crash) when mounted. (CVE-2018-1093)\n\nJann Horn discovered that the Linux kernel's implementation of random seed\ndata reported that it was in a ready state before it had gathered\nsufficient entropy. An attacker could use this to expose sensitive\ninformation. (CVE-2018-1108)\n\nIt was discovered that the procfs filesystem did not properly handle\nprocesses mapping some memory elements onto files. A local attacker could\nuse this to block utilities that examine the procfs filesystem to report\noperating system state, such as ps(1). (CVE-2018-1120)\n\nJann Horn discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly keep xattr information consistent in some\nsituations. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2018-11412)\n\nPiotr Gabriel Kosinski and Daniel Shapira discovered a stack-based buffer\noverflow in the CDROM driver implementation of the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2018-11506)\n\nShankara Pailoor discovered that a race condition existed in the socket\nhandling code in the Linux kernel. A local attacker could use this to cause\na denial of service (system crash). (CVE-2018-12232)\n\nShankara Pailoor discovered that the JFS filesystem implementation in the\nLinux kernel contained a buffer overflow when handling extended attributes.\nA local attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2018-12233)\n\nFelix Wilhelm discovered that the KVM implementation in the Linux kernel\ndid not properly perform permission checks in some situations when nested\nvirtualization is used. An attacker in a guest VM could possibly use this\nto escape into an outer VM or the host OS. (CVE-2018-12904)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly handle an error condition with a corrupted xfs\nimage. An attacker could use this to construct a malicious xfs image that,\nwhen mounted, could cause a denial of service (system crash).\n(CVE-2018-13094)\n\nIt was discovered that the Linux kernel did not properly handle setgid file\ncreation when performed by a non-member of the group. A local attacker\ncould use this to gain elevated privileges. (CVE-2018-13405)\n\nSilvio Cesare discovered that the generic VESA frame buffer driver in the\nLinux kernel contained an integer overflow. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-13406)\n\nJakub Jirasek discovered that multiple use-after-free errors existed in the\nUSB/IP implementation in the Linux kernel. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5814)\n\nIt was discovered that a race condition existed in the ARM Advanced\nMicrocontroller Bus Architecture (AMBA) driver in the Linux kernel that\ncould result in a double free. A local attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-9415)\n\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-1000204)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux-hwe","version":"4.15.0-33.36~16.04.1","description":"Linux hardware enablement (HWE) kernel","is_source":true},{"name":"linux-image-4.15.0-33-generic","version":"4.15.0-33.36~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-33.36~16.04.1","pocket":"security"},{"name":"linux-image-4.15.0-33-generic-lpae","version":"4.15.0-33.36~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-33.36~16.04.1","pocket":"security"},{"name":"linux-image-4.15.0-33-lowlatency","version":"4.15.0-33.36~16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-33.36~16.04.1","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-33-generic","version":"4.15.0-33.36~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-33.36~16.04.1","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-33-lowlatency","version":"4.15.0-33.36~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.15.0-33.36~16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-1000200","CVE-2018-1000204","CVE-2018-10323","CVE-2018-10840","CVE-2018-10881","CVE-2018-1093","CVE-2018-1108","CVE-2018-1120","CVE-2018-11412","CVE-2018-11506","CVE-2018-12232","CVE-2018-12233","CVE-2018-12904","CVE-2018-13094","CVE-2018-13405","CVE-2018-13406","CVE-2018-5814","CVE-2018-9415"]},{"id":"USN-3752-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-08-24T00:33:18.355805","description":"It was discovered that, when attempting to handle an out-of-memory\nsituation, a null pointer dereference could be triggered in the Linux\nkernel in some circumstances. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2018-1000200)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly validate meta-data information. An attacker could\nuse this to construct a malicious xfs image that, when mounted, could cause\na denial of service (system crash). (CVE-2018-10323)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly validate xattr information. An attacker could use\nthis to construct a malicious xfs image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10840)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly keep meta-data information consistent in some\nsituations. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10881)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly handle corrupted meta data in some situations. An\nattacker could use this to specially craft an ext4 filesystem that caused a\ndenial of service (system crash) when mounted. (CVE-2018-1093)\n\nJann Horn discovered that the Linux kernel's implementation of random seed\ndata reported that it was in a ready state before it had gathered\nsufficient entropy. An attacker could use this to expose sensitive\ninformation. (CVE-2018-1108)\n\nIt was discovered that the procfs filesystem did not properly handle\nprocesses mapping some memory elements onto files. A local attacker could\nuse this to block utilities that examine the procfs filesystem to report\noperating system state, such as ps(1). (CVE-2018-1120)\n\nJann Horn discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly keep xattr information consistent in some\nsituations. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2018-11412)\n\nPiotr Gabriel Kosinski and Daniel Shapira discovered a stack-based buffer\noverflow in the CDROM driver implementation of the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2018-11506)\n\nShankara Pailoor discovered that a race condition existed in the socket\nhandling code in the Linux kernel. A local attacker could use this to cause\na denial of service (system crash). (CVE-2018-12232)\n\nShankara Pailoor discovered that the JFS filesystem implementation in the\nLinux kernel contained a buffer overflow when handling extended attributes.\nA local attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2018-12233)\n\nFelix Wilhelm discovered that the KVM implementation in the Linux kernel\ndid not properly perform permission checks in some situations when nested\nvirtualization is used. An attacker in a guest VM could possibly use this\nto escape into an outer VM or the host OS. (CVE-2018-12904)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly handle an error condition with a corrupted xfs\nimage. An attacker could use this to construct a malicious xfs image that,\nwhen mounted, could cause a denial of service (system crash).\n(CVE-2018-13094)\n\nIt was discovered that the Linux kernel did not properly handle setgid file\ncreation when performed by a non-member of the group. A local attacker\ncould use this to gain elevated privileges. (CVE-2018-13405)\n\nSilvio Cesare discovered that the generic VESA frame buffer driver in the\nLinux kernel contained an integer overflow. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-13406)\n\nJakub Jirasek discovered that multiple use-after-free errors existed in the\nUSB/IP implementation in the Linux kernel. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5814)\n\nIt was discovered that a race condition existed in the ARM Advanced\nMicrocontroller Bus Architecture (AMBA) driver in the Linux kernel that\ncould result in a double free. A local attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-9415)\n\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-1000204)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"linux","version":"4.15.0-33.36","description":"Linux kernel","is_source":true},{"name":"linux-aws","version":"4.15.0-1020.20","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-gcp","version":"4.15.0-1018.19","description":"Linux kernel for Google Cloud Platform (GCP) systems","is_source":true},{"name":"linux-kvm","version":"4.15.0-1020.20","description":"Linux kernel for cloud environments","is_source":true},{"name":"linux-raspi2","version":"4.15.0-1021.23","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-image-4.15.0-1020-aws","version":"4.15.0-1020.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1020.20","pocket":"security"},{"name":"linux-image-4.15.0-1020-kvm","version":"4.15.0-1020.20","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.15.0-1020.20","pocket":"security"},{"name":"linux-image-4.15.0-1021-raspi2","version":"4.15.0-1021.23","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.15.0-1021.23","pocket":"security"},{"name":"linux-image-4.15.0-33-generic","version":"4.15.0-33.36","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-33.36","pocket":"security"},{"name":"linux-image-4.15.0-33-generic-lpae","version":"4.15.0-33.36","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-33.36","pocket":"security"},{"name":"linux-image-4.15.0-33-lowlatency","version":"4.15.0-33.36","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-33.36","pocket":"security"},{"name":"linux-image-4.15.0-33-snapdragon","version":"4.15.0-33.36","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-33.36","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-1018-gcp","version":"4.15.0-1018.19","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1018.19","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-33-generic","version":"4.15.0-33.36","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-33.36","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-33-lowlatency","version":"4.15.0-33.36","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.15.0-33.36","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-1000200","CVE-2018-1000204","CVE-2018-10323","CVE-2018-10840","CVE-2018-10881","CVE-2018-1093","CVE-2018-1108","CVE-2018-1120","CVE-2018-11412","CVE-2018-11506","CVE-2018-12232","CVE-2018-12233","CVE-2018-12904","CVE-2018-13094","CVE-2018-13405","CVE-2018-13406","CVE-2018-5814","CVE-2018-9415"]},{"id":"USN-3752-3","title":"Linux kernel (Azure, GCP, OEM) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-08-28T18:52:56.281160","description":"It was discovered that, when attempting to handle an out-of-memory\nsituation, a null pointer dereference could be triggered in the Linux\nkernel in some circumstances. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2018-1000200)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly validate meta-data information. An attacker could\nuse this to construct a malicious xfs image that, when mounted, could cause\na denial of service (system crash). (CVE-2018-10323)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly validate xattr information. An attacker could use\nthis to construct a malicious xfs image that, when mounted, could cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-10840)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly keep meta-data information consistent in some\nsituations. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10881)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly handle corrupted meta data in some situations. An\nattacker could use this to specially craft an ext4 filesystem that caused a\ndenial of service (system crash) when mounted. (CVE-2018-1093)\n\nJann Horn discovered that the Linux kernel's implementation of random seed\ndata reported that it was in a ready state before it had gathered\nsufficient entropy. An attacker could use this to expose sensitive\ninformation. (CVE-2018-1108)\n\nIt was discovered that the procfs filesystem did not properly handle\nprocesses mapping some memory elements onto files. A local attacker could\nuse this to block utilities that examine the procfs filesystem to report\noperating system state, such as ps(1). (CVE-2018-1120)\n\nJann Horn discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly keep xattr information consistent in some\nsituations. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2018-11412)\n\nPiotr Gabriel Kosinski and Daniel Shapira discovered a stack-based buffer\noverflow in the CDROM driver implementation of the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2018-11506)\n\nShankara Pailoor discovered that a race condition existed in the socket\nhandling code in the Linux kernel. A local attacker could use this to cause\na denial of service (system crash). (CVE-2018-12232)\n\nShankara Pailoor discovered that the JFS filesystem implementation in the\nLinux kernel contained a buffer overflow when handling extended attributes.\nA local attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2018-12233)\n\nFelix Wilhelm discovered that the KVM implementation in the Linux kernel\ndid not properly perform permission checks in some situations when nested\nvirtualization is used. An attacker in a guest VM could possibly use this\nto escape into an outer VM or the host OS. (CVE-2018-12904)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly handle an error condition with a corrupted xfs\nimage. An attacker could use this to construct a malicious xfs image that,\nwhen mounted, could cause a denial of service (system crash).\n(CVE-2018-13094)\n\nIt was discovered that the Linux kernel did not properly handle setgid file\ncreation when performed by a non-member of the group. A local attacker\ncould use this to gain elevated privileges. (CVE-2018-13405)\n\nSilvio Cesare discovered that the generic VESA frame buffer driver in the\nLinux kernel contained an integer overflow. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-13406)\n\nJakub Jirasek discovered that multiple use-after-free errors existed in the\nUSB/IP implementation in the Linux kernel. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5814)\n\nIt was discovered that a race condition existed in the ARM Advanced\nMicrocontroller Bus Architecture (AMBA) driver in the Linux kernel that\ncould result in a double free. A local attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-9415)\n\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-1000204)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"linux-azure","version":"4.15.0-1022.23","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-oem","version":"4.15.0-1017.20","description":"Linux kernel for OEM processors","is_source":true},{"name":"linux-image-unsigned-4.15.0-1017-oem","version":"4.15.0-1017.20","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-oem","version_link":"https://launchpad.net/ubuntu/+source/linux-oem/4.15.0-1017.20","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-1022-azure","version":"4.15.0-1022.23","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1022.23","pocket":"security"}],"xenial":[{"name":"linux-azure","version":"4.15.0-1022.22~16.04.1","description":"Linux kernel for Microsoft Azure Cloud systems","is_source":true},{"name":"linux-gcp","version":"4.15.0-1018.19~16.04.2","description":"Linux kernel for Google Cloud Platform (GCP) systems","is_source":true},{"name":"linux-image-unsigned-4.15.0-1018-gcp","version":"4.15.0-1018.19~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-gcp","version_link":"https://launchpad.net/ubuntu/+source/linux-gcp/4.15.0-1018.19~16.04.2","pocket":"security"},{"name":"linux-image-unsigned-4.15.0-1022-azure","version":"4.15.0-1022.22~16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-azure","version_link":"https://launchpad.net/ubuntu/+source/linux-azure/4.15.0-1022.22~16.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2018-1000200","CVE-2018-1000204","CVE-2018-10323","CVE-2018-10840","CVE-2018-10881","CVE-2018-1093","CVE-2018-1108","CVE-2018-1120","CVE-2018-11412","CVE-2018-11506","CVE-2018-12232","CVE-2018-12233","CVE-2018-12904","CVE-2018-13094","CVE-2018-13405","CVE-2018-13406","CVE-2018-5814","CVE-2018-9415"]},{"id":"USN-3696-2","title":"Linux kernel (Xenial HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-07-02T19:45:37.331006","description":"USN-3696-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu\n14.04 LTS.\n\nIt was discovered that an integer overflow existed in the perf subsystem of\nthe Linux kernel. A local attacker could use this to cause a denial of\nservice (system crash). (CVE-2017-18255)\n\nWei Fang discovered an integer overflow in the F2FS filesystem\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service. (CVE-2017-18257)\n\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-1000204)\n\nIt was discovered that the wait4() system call in the Linux kernel did not\nproperly validate its arguments in some situations. A local attacker could\npossibly use this to cause a denial of service. (CVE-2018-10087)\n\nIt was discovered that the kill() system call implementation in the Linux\nkernel did not properly validate its arguments in some situations. A local\nattacker could possibly use this to cause a denial of service.\n(CVE-2018-10124)\n\nJulian Stecklina and Thomas Prescher discovered that FPU register states\n(such as MMX, SSE, and AVX registers) which are lazily restored are\npotentially vulnerable to a side channel attack. A local attacker could use\nthis to expose sensitive information. (CVE-2018-3665)\n\nJakub Jirasek discovered that multiple use-after-errors existed in the\nUSB/IP implementation in the Linux kernel. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5814)\n\nIt was discovered that an information leak vulnerability existed in the\nfloppy driver in the Linux kernel. A local attacker could use this to\nexpose sensitive information (kernel memory). (CVE-2018-7755)\n\nSeunghun Han discovered an information leak in the ACPI handling code in\nthe Linux kernel when handling early termination of ACPI table loading. A\nlocal attacker could use this to expose sensitive informal (kernel address\nlocations). (CVE-2017-13695)\n\nIt was discovered that a memory leak existed in the Serial Attached SCSI\n(SAS) implementation in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (memory exhaustion).\n(CVE-2018-10021)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-aws","version":"4.4.0-1024.25","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-lts-xenial","version":"4.4.0-130.156~14.04.1","description":"Linux hardware enablement kernel from Xenial for Trusty","is_source":true},{"name":"linux-image-4.4.0-1024-aws","version":"4.4.0-1024.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1024.25","pocket":"security"},{"name":"linux-image-4.4.0-130-generic","version":"4.4.0-130.156~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-130.156~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-130-generic-lpae","version":"4.4.0-130.156~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-130.156~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-130-lowlatency","version":"4.4.0-130.156~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-130.156~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-130-powerpc-e500mc","version":"4.4.0-130.156~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-130.156~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-130-powerpc-smp","version":"4.4.0-130.156~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-130.156~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-130-powerpc64-emb","version":"4.4.0-130.156~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-130.156~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-130-powerpc64-smp","version":"4.4.0-130.156~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-130.156~14.04.1","pocket":"security"},{"name":"linux-image-extra-4.4.0-130-generic","version":"4.4.0-130.156~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-130.156~14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-13695","CVE-2017-18255","CVE-2017-18257","CVE-2018-1000204","CVE-2018-10021","CVE-2018-10087","CVE-2018-10124","CVE-2018-3665","CVE-2018-5814","CVE-2018-7755"]},{"id":"USN-3696-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-07-02T19:42:17.966655","description":"It was discovered that an integer overflow existed in the perf subsystem of\nthe Linux kernel. A local attacker could use this to cause a denial of\nservice (system crash). (CVE-2017-18255)\n\nWei Fang discovered an integer overflow in the F2FS filesystem\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service. (CVE-2017-18257)\n\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-1000204)\n\nIt was discovered that the wait4() system call in the Linux kernel did not\nproperly validate its arguments in some situations. A local attacker could\npossibly use this to cause a denial of service. (CVE-2018-10087)\n\nIt was discovered that the kill() system call implementation in the Linux\nkernel did not properly validate its arguments in some situations. A local\nattacker could possibly use this to cause a denial of service.\n(CVE-2018-10124)\n\nJulian Stecklina and Thomas Prescher discovered that FPU register states\n(such as MMX, SSE, and AVX registers) which are lazily restored are\npotentially vulnerable to a side channel attack. A local attacker could use\nthis to expose sensitive information. (CVE-2018-3665)\n\nJakub Jirasek discovered that multiple use-after-free errors existed in the\nUSB/IP implementation in the Linux kernel. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5814)\n\nIt was discovered that an information leak vulnerability existed in the\nfloppy driver in the Linux kernel. A local attacker could use this to\nexpose sensitive information (kernel memory). (CVE-2018-7755)\n\nSeunghun Han discovered an information leak in the ACPI handling code in\nthe Linux kernel when handling early termination of ACPI table loading. A\nlocal attacker could use this to expose sensitive informal (kernel address\nlocations). (CVE-2017-13695)\n\nIt was discovered that a memory leak existed in the Serial Attached SCSI\n(SAS) implementation in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (memory exhaustion).\n(CVE-2018-10021)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux","version":"4.4.0-130.156","description":"Linux kernel","is_source":true},{"name":"linux-aws","version":"4.4.0-1062.71","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-kvm","version":"4.4.0-1029.34","description":"Linux kernel for cloud environments","is_source":true},{"name":"linux-raspi2","version":"4.4.0-1092.100","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-snapdragon","version":"4.4.0-1095.100","description":"Linux kernel for Snapdragon processors","is_source":true},{"name":"linux-image-4.4.0-1029-kvm","version":"4.4.0-1029.34","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-kvm","version_link":"https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1029.34","pocket":"security"},{"name":"linux-image-4.4.0-1062-aws","version":"4.4.0-1062.71","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1062.71","pocket":"security"},{"name":"linux-image-4.4.0-1092-raspi2","version":"4.4.0-1092.100","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1092.100","pocket":"security"},{"name":"linux-image-4.4.0-1095-snapdragon","version":"4.4.0-1095.100","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon","version_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1095.100","pocket":"security"},{"name":"linux-image-4.4.0-130-generic","version":"4.4.0-130.156","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-130.156","pocket":"security"},{"name":"linux-image-4.4.0-130-generic-lpae","version":"4.4.0-130.156","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-130.156","pocket":"security"},{"name":"linux-image-4.4.0-130-lowlatency","version":"4.4.0-130.156","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-130.156","pocket":"security"},{"name":"linux-image-4.4.0-130-powerpc-e500mc","version":"4.4.0-130.156","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-130.156","pocket":"security"},{"name":"linux-image-4.4.0-130-powerpc-smp","version":"4.4.0-130.156","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-130.156","pocket":"security"},{"name":"linux-image-4.4.0-130-powerpc64-emb","version":"4.4.0-130.156","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-130.156","pocket":"security"},{"name":"linux-image-4.4.0-130-powerpc64-smp","version":"4.4.0-130.156","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-130.156","pocket":"security"},{"name":"linux-image-extra-4.4.0-130-generic","version":"4.4.0-130.156","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-130.156","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-13695","CVE-2017-18255","CVE-2017-18257","CVE-2018-1000204","CVE-2018-10021","CVE-2018-10087","CVE-2018-10124","CVE-2018-3665","CVE-2018-5814","CVE-2018-7755"]},{"id":"USN-3754-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-08-24T00:38:00.274205","description":"Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel\ndid not properly validate meta block groups. An attacker with physical\naccess could use this to specially craft an ext4 image that causes a denial\nof service (system crash). (CVE-2016-10208)\n\nIt was discovered that an information disclosure vulnerability existed in\nthe ACPI implementation of the Linux kernel. A local attacker could use\nthis to expose sensitive information (kernel memory addresses).\n(CVE-2017-11472)\n\nIt was discovered that a buffer overflow existed in the ACPI table parsing\nimplementation in the Linux kernel. A local attacker could use this to\nconstruct a malicious ACPI table that, when loaded, caused a denial of\nservice (system crash) or possibly execute arbitrary code.\n(CVE-2017-11473)\n\nIt was discovered that the generic SCSI driver in the Linux kernel did not\nproperly initialize data returned to user space in some situations. A local\nattacker could use this to expose sensitive information (kernel memory).\n(CVE-2017-14991)\n\nIt was discovered that a race condition existed in the packet fanout\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-15649)\n\nAndrey Konovalov discovered that the Ultra Wide Band driver in the Linux\nkernel did not properly check for an error condition. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-16526)\n\nAndrey Konovalov discovered that the ALSA subsystem in the Linux kernel\ncontained a use-after-free vulnerability. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-16527)\n\nAndrey Konovalov discovered that the ALSA subsystem in the Linux kernel did\nnot properly validate USB audio buffer descriptors. A physically proximate\nattacker could use this cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2017-16529)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB interface association descriptors. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-16531)\n\nAndrey Konovalov discovered that the usbtest device driver in the Linux\nkernel did not properly validate endpoint metadata. A physically proximate\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-16532)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB HID descriptors. A physically proximate attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2017-16533)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB BOS metadata. A physically proximate attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2017-16535)\n\nAndrey Konovalov discovered that the Conexant cx231xx USB video capture\ndriver in the Linux kernel did not properly validate interface descriptors.\nA physically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16536)\n\nAndrey Konovalov discovered that the SoundGraph iMON USB driver in the\nLinux kernel did not properly validate device metadata. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-16537)\n\nIt was discovered that the DM04/QQBOX USB driver in the Linux kernel did\nnot properly handle device attachment and warm-start. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-16538)\n\nAndrey Konovalov discovered an out-of-bounds read in the GTCO digitizer USB\ndriver for the Linux kernel. A physically proximate attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-16643)\n\nAndrey Konovalov discovered that the video4linux driver for Hauppauge HD\nPVR USB devices in the Linux kernel did not properly handle some error\nconditions. A physically proximate attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2017-16644)\n\nAndrey Konovalov discovered that the IMS Passenger Control Unit USB driver\nin the Linux kernel did not properly validate device descriptors. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16645)\n\nAndrey Konovalov discovered that the QMI WWAN USB driver did not properly\nvalidate device descriptors. A physically proximate attacker could use this\nto cause a denial of service (system crash). (CVE-2017-16650)\n\nIt was discovered that the USB Virtual Host Controller Interface (VHCI)\ndriver in the Linux kernel contained an information disclosure\nvulnerability. A physically proximate attacker could use this to expose\nsensitive information (kernel memory). (CVE-2017-16911)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not validate endpoint numbers. A remote attacker could use this to\ncause a denial of service (system crash). (CVE-2017-16912)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not properly validate CMD_SUBMIT packets. A remote attacker could use\nthis to cause a denial of service (excessive memory consumption).\n(CVE-2017-16913)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ncontained a NULL pointer dereference error. A remote attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-16914)\n\nIt was discovered that the core USB subsystem in the Linux kernel did not\nvalidate the number of configurations and interfaces in a device. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-17558)\n\nIt was discovered that an integer overflow existed in the perf subsystem of\nthe Linux kernel. A local attacker could use this to cause a denial of\nservice (system crash). (CVE-2017-18255)\n\nIt was discovered that the keyring subsystem in the Linux kernel did not\nproperly prevent a user from creating keyrings for other users. A local\nattacker could use this cause a denial of service or expose sensitive\ninformation. (CVE-2017-18270)\n\nAndy Lutomirski and Willy Tarreau discovered that the KVM implementation in\nthe Linux kernel did not properly emulate instructions on the SS segment\nregister. A local attacker in a guest virtual machine could use this to\ncause a denial of service (guest OS crash) or possibly gain administrative\nprivileges in the guest OS. (CVE-2017-2583)\n\nDmitry Vyukov discovered that the KVM implementation in the Linux kernel\nimproperly emulated certain instructions. A local attacker could use this\nto obtain sensitive information (kernel memory). (CVE-2017-2584)\n\nIt was discovered that the KLSI KL5KUSB105 serial-to-USB device driver in\nthe Linux kernel did not properly initialize memory related to logging. A\nlocal attacker could use this to expose sensitive information (kernel\nmemory). (CVE-2017-5549)\n\nAndrey Konovalov discovered an out-of-bounds access in the IPv6 Generic\nRouting Encapsulation (GRE) tunneling implementation in the Linux kernel.\nAn attacker could use this to possibly expose sensitive information.\n(CVE-2017-5897)\n\nAndrey Konovalov discovered that the LLC subsytem in the Linux kernel did\nnot properly set up a destructor in certain situations. A local attacker\ncould use this to cause a denial of service (system crash). (CVE-2017-6345)\n\nDmitry Vyukov discovered race conditions in the Infrared (IrDA) subsystem\nin the Linux kernel. A local attacker could use this to cause a denial of\nservice (deadlock). (CVE-2017-6348)\n\nAndy Lutomirski discovered that the KVM implementation in the Linux kernel\nwas vulnerable to a debug exception error when single-stepping through a\nsyscall. A local attacker in a non-Linux guest vm could possibly use this\nto gain administrative privileges in the guest vm. (CVE-2017-7518)\n\nTuomas Haanpää and Ari Kauppi discovered that the NFSv2 and NFSv3 server\nimplementations in the Linux kernel did not properly handle certain long\nRPC replies. A remote attacker could use this to cause a denial of service\n(system crash). (CVE-2017-7645)\n\nPengfei Wang discovered that a race condition existed in the NXP SAA7164 TV\nDecoder driver for the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-8831)\n\nPengfei Wang discovered that the Turtle Beach MultiSound audio device\ndriver in the Linux kernel contained race conditions when fetching from the\nring-buffer. A local attacker could use this to cause a denial of service\n(infinite loop). (CVE-2017-9984, CVE-2017-9985)\n\nIt was discovered that the wait4() system call in the Linux kernel did not\nproperly validate its arguments in some situations. A local attacker could\npossibly use this to cause a denial of service. (CVE-2018-10087)\n\nIt was discovered that the kill() system call implementation in the Linux\nkernel did not properly validate its arguments in some situations. A local\nattacker could possibly use this to cause a denial of service.\n(CVE-2018-10124)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly validate meta-data information. An attacker could\nuse this to construct a malicious xfs image that, when mounted, could cause\na denial of service (system crash). (CVE-2018-10323)\n\nZhong Jiang discovered that a use-after-free vulnerability existed in the\nNUMA memory policy implementation in the Linux kernel. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2018-10675)\n\nWen Xu discovered that a buffer overflow existed in the ext4 filesystem\nimplementation in the Linux kernel. An attacker could use this to construct\na malicious ext4 image that, when mounted, could cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2018-10877)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly keep meta-data information consistent in some\nsituations. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10881)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly handle corrupted meta data in some situations. An\nattacker could use this to specially craft an ext4 filesystem that caused\na denial of service (system crash) when mounted. (CVE-2018-1092)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly handle corrupted meta data in some situations. An\nattacker could use this to specially craft an ext4 filesystem that caused a\ndenial of service (system crash) when mounted. (CVE-2018-1093)\n\nIt was discovered that the cdrom driver in the Linux kernel contained an\nincorrect bounds check. A local attacker could use this to expose sensitive\ninformation (kernel memory). (CVE-2018-10940)\n\nShankara Pailoor discovered that the JFS filesystem implementation in the\nLinux kernel contained a buffer overflow when handling extended attributes.\nA local attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2018-12233)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly handle an error condition with a corrupted xfs\nimage. An attacker could use this to construct a malicious xfs image that,\nwhen mounted, could cause a denial of service (system crash).\n(CVE-2018-13094)\n\nIt was discovered that the Linux kernel did not properly handle setgid file\ncreation when performed by a non-member of the group. A local attacker\ncould use this to gain elevated privileges. (CVE-2018-13405)\n\nSilvio Cesare discovered that the generic VESA frame buffer driver in the\nLinux kernel contained an integer overflow. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-13406)\n\nDaniel Jiang discovered that a race condition existed in the ipv4 ping\nsocket implementation in the Linux kernel. A local privileged attacker\ncould use this to cause a denial of service (system crash). (CVE-2017-2671)\n\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-1000204)\n\nIt was discovered that a memory leak existed in the Serial Attached SCSI\n(SAS) implementation in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (memory exhaustion).\n(CVE-2018-10021)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-157.207","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-157-generic","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-generic-lpae","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-lowlatency","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc-e500","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc-e500mc","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc-smp","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc64-emb","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc64-smp","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-extra-3.13.0-157-generic","version":"3.13.0-157.207","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10208","CVE-2017-11472","CVE-2017-11473","CVE-2017-14991","CVE-2017-15649","CVE-2017-16526","CVE-2017-16527","CVE-2017-16529","CVE-2017-16531","CVE-2017-16532","CVE-2017-16533","CVE-2017-16535","CVE-2017-16536","CVE-2017-16537","CVE-2017-16538","CVE-2017-16643","CVE-2017-16644","CVE-2017-16645","CVE-2017-16650","CVE-2017-16911","CVE-2017-16912","CVE-2017-16913","CVE-2017-16914","CVE-2017-17558","CVE-2017-18255","CVE-2017-18270","CVE-2017-2583","CVE-2017-2584","CVE-2017-2671","CVE-2017-5549","CVE-2017-5897","CVE-2017-6345","CVE-2017-6348","CVE-2017-7518","CVE-2017-7645","CVE-2017-8831","CVE-2017-9984","CVE-2017-9985","CVE-2018-1000204","CVE-2018-10021","CVE-2018-10087","CVE-2018-10124","CVE-2018-10323","CVE-2018-10675","CVE-2018-10877","CVE-2018-10881","CVE-2018-1092","CVE-2018-1093","CVE-2018-10940","CVE-2018-12233","CVE-2018-13094","CVE-2018-13405","CVE-2018-13406"]}]},{"id":"CVE-2018-11040","published":"2018-06-25T15:29:00","updated_at":"2025-08-26T12:03:25.267638+00:00","description":"\nSpring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18\nand older unsupported versions, allows web applications to enable\ncross-domain requests via JSONP (JSON with Padding) through\nAbstractJsonpResponseBodyAdvice for REST controllers and\nMappingJackson2JsonView for browser requests. Both are not enabled by\ndefault in Spring Framework nor Spring Boot, however, when\nMappingJackson2JsonView is configured in an application, JSONP support is\nautomatically ready to use through the \"jsonp\" and \"callback\" JSONP\nparameters, enabling cross-domain requests.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://pivotal.io/security/cve-2018-11040","https://www.cve.org/CVERecord?id=CVE-2018-11040"],"bugs":[""],"patches":{"libspring-java":[]},"tags":{},"packages":[{"name":"libspring-java","source":"https://ubuntu.com/security/cve?package=libspring-java","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libspring-java","debian":"https://tracker.debian.org/pkg/libspring-java","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.3.19-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":52480,"limit":20,"total_results":79316}