{"cves":[{"id":"CVE-2017-7037","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:36:54.177103+00:00","description":"\nAn issue was discovered in certain Apple products. iOS before 10.3.3 is\naffected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows\nis affected. iTunes before 12.6.2 on Windows is affected. tvOS before\n10.2.2 is affected. The issue involves the \"WebKit\" component. It allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.securitytracker.com/id/1038950","https://support.apple.com/HT207921","https://support.apple.com/HT207923","https://support.apple.com/HT207924","https://support.apple.com/HT207927","https://support.apple.com/HT207928","https://webkitgtk.org/security/WSA-2017-0006.html","https://ubuntu.com/security/notices/USN-3376-1","https://www.cve.org/CVERecord?id=CVE-2017-7037"],"bugs":[""],"patches":{"webkit2gtk":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.16.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.16.6-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.16.6-0ubuntu0.17.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3376-1"],"notices":[{"id":"USN-3376-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2017-08-02T12:40:36.388198","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"webkit2gtk","version":"2.16.6-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"}],"zesty":[{"name":"webkit2gtk","version":"2.16.6-0ubuntu0.17.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.16.6-0ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.17.04.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.16.6-0ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.17.04.1"}]},"type":"USN","cves_ids":["CVE-2017-2538","CVE-2017-7018","CVE-2017-7030","CVE-2017-7034","CVE-2017-7037","CVE-2017-7039","CVE-2017-7046","CVE-2017-7048","CVE-2017-7052","CVE-2017-7055","CVE-2017-7056","CVE-2017-7061","CVE-2017-7064"]}]},{"id":"CVE-2017-7034","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:36:54.177103+00:00","description":"\nAn issue was discovered in certain Apple products. iOS before 10.3.3 is\naffected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows\nis affected. iTunes before 12.6.2 on Windows is affected. tvOS before\n10.2.2 is affected. The issue involves the \"WebKit\" component. It allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.securitytracker.com/id/1038950","https://support.apple.com/HT207921","https://support.apple.com/HT207923","https://support.apple.com/HT207924","https://support.apple.com/HT207927","https://support.apple.com/HT207928","https://webkitgtk.org/security/WSA-2017-0006.html","https://ubuntu.com/security/notices/USN-3376-1","https://www.cve.org/CVERecord?id=CVE-2017-7034"],"bugs":[""],"patches":{"webkit2gtk":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.16.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.16.6-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.16.6-0ubuntu0.17.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3376-1"],"notices":[{"id":"USN-3376-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2017-08-02T12:40:36.388198","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"webkit2gtk","version":"2.16.6-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"}],"zesty":[{"name":"webkit2gtk","version":"2.16.6-0ubuntu0.17.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.16.6-0ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.17.04.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.16.6-0ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.17.04.1"}]},"type":"USN","cves_ids":["CVE-2017-2538","CVE-2017-7018","CVE-2017-7030","CVE-2017-7034","CVE-2017-7037","CVE-2017-7039","CVE-2017-7046","CVE-2017-7048","CVE-2017-7052","CVE-2017-7055","CVE-2017-7056","CVE-2017-7061","CVE-2017-7064"]}]},{"id":"CVE-2017-7030","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:36:54.177103+00:00","description":"\nAn issue was discovered in certain Apple products. iOS before 10.3.3 is\naffected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows\nis affected. iTunes before 12.6.2 on Windows is affected. tvOS before\n10.2.2 is affected. The issue involves the \"WebKit\" component. It allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.securitytracker.com/id/1038950","https://support.apple.com/HT207921","https://support.apple.com/HT207923","https://support.apple.com/HT207924","https://support.apple.com/HT207927","https://support.apple.com/HT207928","https://webkitgtk.org/security/WSA-2017-0006.html","https://ubuntu.com/security/notices/USN-3376-1","https://www.cve.org/CVERecord?id=CVE-2017-7030"],"bugs":[""],"patches":{"webkit2gtk":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"artful","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.16.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.16.6-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.16.6-0ubuntu0.17.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3376-1"],"notices":[{"id":"USN-3376-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2017-08-02T12:40:36.388198","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"webkit2gtk","version":"2.16.6-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"}],"zesty":[{"name":"webkit2gtk","version":"2.16.6-0ubuntu0.17.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.16.6-0ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.17.04.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.16.6-0ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.17.04.1"}]},"type":"USN","cves_ids":["CVE-2017-2538","CVE-2017-7018","CVE-2017-7030","CVE-2017-7034","CVE-2017-7037","CVE-2017-7039","CVE-2017-7046","CVE-2017-7048","CVE-2017-7052","CVE-2017-7055","CVE-2017-7056","CVE-2017-7061","CVE-2017-7064"]}]},{"id":"CVE-2017-7018","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:36:49.419664+00:00","description":"\nAn issue was discovered in certain Apple products. iOS before 10.3.3 is\naffected. Safari before 10.1.2 is affected. iCloud before 6.2.2 on Windows\nis affected. iTunes before 12.6.2 on Windows is affected. tvOS before\n10.2.2 is affected. The issue involves the \"WebKit\" component. It allows\nremote attackers to execute arbitrary code or cause a denial of service\n(memory corruption and application crash) via a crafted web site.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.securitytracker.com/id/1038950","https://support.apple.com/HT207921","https://support.apple.com/HT207923","https://support.apple.com/HT207924","https://support.apple.com/HT207927","https://support.apple.com/HT207928","https://webkitgtk.org/security/WSA-2017-0006.html","https://ubuntu.com/security/notices/USN-3376-1","https://www.cve.org/CVERecord?id=CVE-2017-7018"],"bugs":[""],"patches":{"webkit2gtk":[],"webkitgtk":[],"qtwebkit-source":[],"qtwebkit-opensource-src":[],"qtwebkit":[]},"tags":{},"packages":[{"name":"qtwebkit","source":"https://ubuntu.com/security/cve?package=qtwebkit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit","debian":"https://tracker.debian.org/pkg/qtwebkit","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"qtwebkit-opensource-src","source":"https://ubuntu.com/security/cve?package=qtwebkit-opensource-src","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-opensource-src","debian":"https://tracker.debian.org/pkg/qtwebkit-opensource-src","statuses":[{"release_codename":"groovy","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"impish","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"mantic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"qtwebkit-source","source":"https://ubuntu.com/security/cve?package=qtwebkit-source","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qtwebkit-source","debian":"https://tracker.debian.org/pkg/qtwebkit-source","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]},{"name":"webkit2gtk","source":"https://ubuntu.com/security/cve?package=webkit2gtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkit2gtk","debian":"https://tracker.debian.org/pkg/webkit2gtk","statuses":[{"release_codename":"impish","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.16.6","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.16.6-0ubuntu0.16.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.16.6-0ubuntu0.17.04.1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.16.6-1","component":null,"pocket":"security"}]},{"name":"webkitgtk","source":"https://ubuntu.com/security/cve?package=webkitgtk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=webkitgtk","debian":"https://tracker.debian.org/pkg/webkitgtk","statuses":[{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"end of standard support, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":["USN-3376-1"],"notices":[{"id":"USN-3376-1","title":"WebKitGTK+ vulnerabilities","summary":"Several security issues were fixed in WebKitGTK+.\n","instructions":"This update uses a new upstream release, which includes additional bug\nfixes. After a standard system update you need to restart any applications\nthat use WebKitGTK+, such as Epiphany, to make all the necessary changes.\n","references":[],"published":"2017-08-02T12:40:36.388198","description":"A large number of security issues were discovered in the WebKitGTK+ Web and\nJavaScript engines. If a user were tricked into viewing a malicious\nwebsite, a remote attacker could exploit a variety of issues related to web\nbrowser security, including cross-site scripting attacks, denial of service\nattacks, and arbitrary code execution.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"webkit2gtk","version":"2.16.6-0ubuntu0.16.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"gir1.2-javascriptcoregtk-4.0","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"gir1.2-webkit2-4.0","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-18","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-bin","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libjavascriptcoregtk-4.0-dev","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-37-gtk2","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-dev","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"},{"name":"libwebkit2gtk-4.0-doc","version":"2.16.6-0ubuntu0.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.16.04.1","pocket":"security"}],"zesty":[{"name":"webkit2gtk","version":"2.16.6-0ubuntu0.17.04.1","description":"Web content engine library for GTK+","is_source":true},{"name":"libjavascriptcoregtk-4.0-18","version":"2.16.6-0ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.17.04.1"},{"name":"libwebkit2gtk-4.0-37","version":"2.16.6-0ubuntu0.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/webkit2gtk","version_link":"https://launchpad.net/ubuntu/+source/webkit2gtk/2.16.6-0ubuntu0.17.04.1"}]},"type":"USN","cves_ids":["CVE-2017-2538","CVE-2017-7018","CVE-2017-7030","CVE-2017-7034","CVE-2017-7037","CVE-2017-7039","CVE-2017-7046","CVE-2017-7048","CVE-2017-7052","CVE-2017-7055","CVE-2017-7056","CVE-2017-7061","CVE-2017-7064"]}]},{"id":"CVE-2017-11478","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:20:52.263840+00:00","description":"\nThe ReadOneDJVUImage function in coders/djvu.c in ImageMagick through\n6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial\nof service (infinite loop and CPU consumption) via a malformed DJVU image.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is 0072-CPU-exhaustion-in-ReadOneDJVUImag.patch"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3363-1","https://www.cve.org/CVERecord?id=CVE-2017-11478"],"bugs":["https://github.com/ImageMagick/ImageMagick/issues/528","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867826"],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/78b819628b6a9429f0c33b72e695b4df0b32faea"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"upstream","status":"released","description":"8:6.9.7.4+dfsg-12","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.8","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.8","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8:6.9.7.4+dfsg-3ubuntu1.2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3363-1"],"notices":[{"id":"USN-3363-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-07-24T16:42:44.364124","description":"It was discovered that ImageMagick incorrectly handled certain malformed\nimage files. If a user or automated system using ImageMagick were tricked\ninto opening a specially crafted image, an attacker could exploit this to\ncause a denial of service or possibly execute code with the privileges of\nthe user invoking the program.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.7.7.10-6ubuntu3.8","pocket":"security"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.8","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.8.9.9-7ubuntu5.8","pocket":"security"}],"zesty":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-3ubuntu1.2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-3ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":"https://launchpad.net/ubuntu/+source/imagemagick/8:6.9.7.4+dfsg-3ubuntu1.2"}]},"type":"USN","cves_ids":["CVE-2017-10928","CVE-2017-11141","CVE-2017-11170","CVE-2017-11188","CVE-2017-11352","CVE-2017-11360","CVE-2017-11447","CVE-2017-11448","CVE-2017-11449","CVE-2017-11450","CVE-2017-11478","CVE-2017-9261","CVE-2017-9262","CVE-2017-9405","CVE-2017-9407","CVE-2017-9409","CVE-2017-9439","CVE-2017-9440","CVE-2017-9501"]}]},{"id":"CVE-2017-11473","published":"2017-07-20T00:00:00","updated_at":"2026-07-04T07:42:56.495954+00:00","description":"\nBuffer overflow in the mp_override_legacy_irq() function in\narch/x86/kernel/acpi/boot.c in the Linux kernel through 3.2 allows local\nusers to gain privileges via a crafted ACPI table.","ubuntu_description":"\nIt was discovered that a buffer overflow existed in the ACPI table parsing\nimplementation in the Linux kernel. A local attacker could use this to\nconstruct a malicious ACPI table that, when loaded, caused a denial of\nservice (system crash) or possibly execute arbitrary code.","notes":[],"codename":null,"priority":"low","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip.git/commit/?id=70ac67826602edf8c0ccb413e5ba7eacf597a60c","https://ubuntu.com/security/notices/USN-3754-1","https://www.cve.org/CVERecord?id=CVE-2017-11473"],"bugs":[""],"patches":{"linux":["break-fix: - dad5ab0db8deac535d03e3fe3d8f2892173fa6a4"],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-azure-edge":[],"linux-hwe-5.4":[],"linux-hwe-5.15":[],"linux-hwe-6.8":[],"linux-aws-5.4":[],"linux-aws-5.15":[],"linux-aws-hwe":[],"linux-azure-4.15":[],"linux-azure-5.4":[],"linux-azure-5.15":[],"linux-azure-fde":[],"linux-azure-fde-5.15":[],"linux-bluefield":[],"linux-fips":[],"linux-aws-fips":[],"linux-azure-fips":[],"linux-gcp-fips":[],"linux-gcp-4.15":[],"linux-gcp-5.4":[],"linux-gcp-5.15":[],"linux-gkeop":[],"linux-gkeop-5.15":[],"linux-ibm":[],"linux-ibm-5.4":[],"linux-ibm-5.15":[],"linux-intel":[],"linux-intel-iotg":[],"linux-intel-iotg-5.15":[],"linux-iot":[],"linux-intel-iot-realtime":[],"linux-lowlatency":[],"linux-lowlatency-hwe-5.15":[],"linux-lowlatency-hwe-6.8":[],"linux-nvidia":[],"linux-nvidia-6.5":[],"linux-nvidia-6.8":[],"linux-nvidia-lowlatency":[],"linux-oracle":[],"linux-oracle-5.4":[],"linux-oracle-5.15":[],"linux-oem-6.8":[],"linux-raspi":[],"linux-raspi-5.4":[],"linux-raspi-realtime":[],"linux-realtime":[],"linux-riscv":[],"linux-riscv-5.15":[],"linux-riscv-6.8":[],"linux-xilinx-zynqmp":[],"linux-aws-6.8":[],"linux-gcp-6.8":[],"linux-oracle-6.8":[],"linux-azure-6.8":[],"linux-oem-6.11":[],"linux-hwe-6.11":[],"linux-hwe-6.14":[],"linux-aws-6.14":[],"linux-azure-6.11":[],"linux-azure-nvidia":[],"linux-gcp-6.11":[],"linux-gcp-6.14":[],"linux-ibm-6.8":[],"linux-lowlatency-hwe-6.11":[],"linux-nvidia-tegra":[],"linux-nvidia-tegra-5.15":[],"linux-nvidia-tegra-igx":[],"linux-oracle-6.14":[],"linux-oem-6.14":[],"linux-riscv-6.14":[],"linux-nvidia-6.11":[],"linux-realtime-6.8":[],"linux-realtime-6.14":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux-aws-fips","source":"https://ubuntu.com/security/cve?package=linux-aws-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-fips","debian":"https://tracker.debian.org/pkg/linux-aws-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1052.57+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-2000.4","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips2","component":null,"pocket":"fips"}]},{"name":"linux-azure-fips","source":"https://ubuntu.com/security/cve?package=linux-azure-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fips","debian":"https://tracker.debian.org/pkg/linux-azure-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1058.66+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1022.22+fips1","component":null,"pocket":"fips"}]},{"name":"linux-gcp-fips","source":"https://ubuntu.com/security/cve?package=linux-gcp-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-fips","debian":"https://tracker.debian.org/pkg/linux-gcp-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1048.56+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips1","component":null,"pocket":"fips"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.12.0-11.12","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-20.21","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-157.207","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-93.116","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-16.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-20.21","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-9.12","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-19.19","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1007.7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1032.41","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1007.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1008.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1008.8","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-aws-5.15","source":"https://ubuntu.com/security/cve?package=linux-aws-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.15","debian":"https://tracker.debian.org/pkg/linux-aws-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.19~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-5.4","source":"https://ubuntu.com/security/cve?package=linux-aws-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.4","debian":"https://tracker.debian.org/pkg/linux-aws-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1020.20~18.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-6.14","source":"https://ubuntu.com/security/cve?package=linux-aws-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.14","debian":"https://tracker.debian.org/pkg/linux-aws-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-aws-6.8","source":"https://ubuntu.com/security/cve?package=linux-aws-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.8","debian":"https://tracker.debian.org/pkg/linux-aws-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1009.9~22.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1031.33~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1009.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-1005.7","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1009.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1006.6","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1006.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1082.92","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.8~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1022.22~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-6.11","source":"https://ubuntu.com/security/cve?package=linux-azure-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.11","debian":"https://tracker.debian.org/pkg/linux-azure-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-azure-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-azure-6.8","source":"https://ubuntu.com/security/cve?package=linux-azure-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.8","debian":"https://tracker.debian.org/pkg/linux-azure-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.18.0-1003.3~18.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde","source":"https://ubuntu.com/security/cve?package=linux-azure-fde","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde","debian":"https://tracker.debian.org/pkg/linux-azure-fde","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1019.24.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.14.0-1012.12","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1041.48","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-azure-fde-5.15]","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-fde-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]},{"name":"linux-azure-nvidia","source":"https://ubuntu.com/security/cve?package=linux-azure-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-nvidia","debian":"https://tracker.debian.org/pkg/linux-azure-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1013.14","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-bluefield","source":"https://ubuntu.com/security/cve?package=linux-bluefield","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-bluefield","debian":"https://tracker.debian.org/pkg/linux-bluefield","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1011.14","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-fips","source":"https://ubuntu.com/security/cve?package=linux-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fips","debian":"https://tracker.debian.org/pkg/linux-fips","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-92.102+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1017.22~recert1","component":null,"pocket":"fips"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1011.12","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.8","component":null,"pocket":"fips"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1006.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-1002.5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1006.6","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1003.3","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1071.81","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.15","debian":"https://tracker.debian.org/pkg/linux-gcp-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1006.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.4","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.4","debian":"https://tracker.debian.org/pkg/linux-gcp-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.11","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.11","debian":"https://tracker.debian.org/pkg/linux-gcp-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-gcp-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.14","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.14","debian":"https://tracker.debian.org/pkg/linux-gcp-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.8","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.8","debian":"https://tracker.debian.org/pkg/linux-gcp-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1010.11~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1028.28","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop","source":"https://ubuntu.com/security/cve?package=linux-gkeop","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop","debian":"https://tracker.debian.org/pkg/linux-gkeop","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1008.9","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop-5.15","source":"https://ubuntu.com/security/cve?package=linux-gkeop-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop-5.15","debian":"https://tracker.debian.org/pkg/linux-gkeop-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-32.35~16.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-37.41~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.14","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.14","debian":"https://tracker.debian.org/pkg/linux-hwe-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-24.24~24.04.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-26.29~16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.0.0-15.16~18.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm","source":"https://ubuntu.com/security/cve?package=linux-ibm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm","debian":"https://tracker.debian.org/pkg/linux-ibm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1009.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.15","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.15","debian":"https://tracker.debian.org/pkg/linux-ibm-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1034.37~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.4","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.4","debian":"https://tracker.debian.org/pkg/linux-ibm-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1010.11~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-6.8","source":"https://ubuntu.com/security/cve?package=linux-ibm-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-6.8","debian":"https://tracker.debian.org/pkg/linux-ibm-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-intel","source":"https://ubuntu.com/security/cve?package=linux-intel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel","debian":"https://tracker.debian.org/pkg/linux-intel","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iot-realtime","source":"https://ubuntu.com/security/cve?package=linux-intel-iot-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iot-realtime","debian":"https://tracker.debian.org/pkg/linux-intel-iot-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1021.26","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg","debian":"https://tracker.debian.org/pkg/linux-intel-iotg","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1004.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg-5.15","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg-5.15","debian":"https://tracker.debian.org/pkg/linux-intel-iotg-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-iot","source":"https://ubuntu.com/security/cve?package=linux-iot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-iot","debian":"https://tracker.debian.org/pkg/linux-iot","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1008.8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1007.12","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1008.8","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency","debian":"https://tracker.debian.org/pkg/linux-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-22.22","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"replaced by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needs-triage]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-93.116~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-nvidia","source":"https://ubuntu.com/security/cve?package=linux-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia","debian":"https://tracker.debian.org/pkg/linux-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1005.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.11","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.11","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1002.2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.5","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.5","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.5.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.8","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.8","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-nvidia-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-lowlatency","debian":"https://tracker.debian.org/pkg/linux-nvidia-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1009.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1013.13","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-5.15","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-5.15","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1009.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-igx","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-igx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-igx","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-igx","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1004.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1004.5","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.11","source":"https://ubuntu.com/security/cve?package=linux-oem-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.11","debian":"https://tracker.debian.org/pkg/linux-oem-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.14","source":"https://ubuntu.com/security/cve?package=linux-oem-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.14","debian":"https://tracker.debian.org/pkg/linux-oem-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1005.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-oem-6.8","source":"https://ubuntu.com/security/cve?package=linux-oem-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.8","debian":"https://tracker.debian.org/pkg/linux-oem-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1010.10","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1008.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1008.10~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1005.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1006.6","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.15","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.15","debian":"https://tracker.debian.org/pkg/linux-oracle-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.4","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.4","debian":"https://tracker.debian.org/pkg/linux-oracle-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.14","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.14","debian":"https://tracker.debian.org/pkg/linux-oracle-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.8","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.8","debian":"https://tracker.debian.org/pkg/linux-oracle-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1006.6~22.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1005.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1004.4","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1013.13~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi-realtime","source":"https://ubuntu.com/security/cve?package=linux-raspi-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-realtime","debian":"https://tracker.debian.org/pkg/linux-raspi-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.7.0-2001.1","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.13.0-1004.4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1010.11","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1071.79","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-1005.5","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1010.11","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [replaced by linux-raspi]","component":null,"pocket":"security"}]},{"name":"linux-realtime","source":"https://ubuntu.com/security/cve?package=linux-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime","debian":"https://tracker.debian.org/pkg/linux-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1006.6","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.1-1015.16","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.14","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.14","debian":"https://tracker.debian.org/pkg/linux-realtime-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1003.3~24.04.3","component":null,"pocket":"realtime"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.8","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.8","debian":"https://tracker.debian.org/pkg/linux-realtime-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.1-1004.4~22.04.1","component":null,"pocket":"realtime"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-riscv-5.8]","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.15","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.15","debian":"https://tracker.debian.org/pkg/linux-riscv-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.17~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.14","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.14","debian":"https://tracker.debian.org/pkg/linux-riscv-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-22.22.1~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.8","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.8","debian":"https://tracker.debian.org/pkg/linux-riscv-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.4.0-1073.78","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1073.78","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"4.4.0-1073.78","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-xilinx-zynqmp","source":"https://ubuntu.com/security/cve?package=linux-xilinx-zynqmp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-xilinx-zynqmp","debian":"https://tracker.debian.org/pkg/linux-xilinx-zynqmp","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1020.24","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1022.26","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.13~rc2, 4.4.79","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3754-1"],"notices":[{"id":"USN-3754-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-08-24T00:38:00.274205","description":"Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel\ndid not properly validate meta block groups. An attacker with physical\naccess could use this to specially craft an ext4 image that causes a denial\nof service (system crash). (CVE-2016-10208)\n\nIt was discovered that an information disclosure vulnerability existed in\nthe ACPI implementation of the Linux kernel. A local attacker could use\nthis to expose sensitive information (kernel memory addresses).\n(CVE-2017-11472)\n\nIt was discovered that a buffer overflow existed in the ACPI table parsing\nimplementation in the Linux kernel. A local attacker could use this to\nconstruct a malicious ACPI table that, when loaded, caused a denial of\nservice (system crash) or possibly execute arbitrary code.\n(CVE-2017-11473)\n\nIt was discovered that the generic SCSI driver in the Linux kernel did not\nproperly initialize data returned to user space in some situations. A local\nattacker could use this to expose sensitive information (kernel memory).\n(CVE-2017-14991)\n\nIt was discovered that a race condition existed in the packet fanout\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-15649)\n\nAndrey Konovalov discovered that the Ultra Wide Band driver in the Linux\nkernel did not properly check for an error condition. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-16526)\n\nAndrey Konovalov discovered that the ALSA subsystem in the Linux kernel\ncontained a use-after-free vulnerability. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-16527)\n\nAndrey Konovalov discovered that the ALSA subsystem in the Linux kernel did\nnot properly validate USB audio buffer descriptors. A physically proximate\nattacker could use this cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2017-16529)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB interface association descriptors. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-16531)\n\nAndrey Konovalov discovered that the usbtest device driver in the Linux\nkernel did not properly validate endpoint metadata. A physically proximate\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-16532)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB HID descriptors. A physically proximate attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2017-16533)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB BOS metadata. A physically proximate attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2017-16535)\n\nAndrey Konovalov discovered that the Conexant cx231xx USB video capture\ndriver in the Linux kernel did not properly validate interface descriptors.\nA physically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16536)\n\nAndrey Konovalov discovered that the SoundGraph iMON USB driver in the\nLinux kernel did not properly validate device metadata. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-16537)\n\nIt was discovered that the DM04/QQBOX USB driver in the Linux kernel did\nnot properly handle device attachment and warm-start. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-16538)\n\nAndrey Konovalov discovered an out-of-bounds read in the GTCO digitizer USB\ndriver for the Linux kernel. A physically proximate attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-16643)\n\nAndrey Konovalov discovered that the video4linux driver for Hauppauge HD\nPVR USB devices in the Linux kernel did not properly handle some error\nconditions. A physically proximate attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2017-16644)\n\nAndrey Konovalov discovered that the IMS Passenger Control Unit USB driver\nin the Linux kernel did not properly validate device descriptors. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16645)\n\nAndrey Konovalov discovered that the QMI WWAN USB driver did not properly\nvalidate device descriptors. A physically proximate attacker could use this\nto cause a denial of service (system crash). (CVE-2017-16650)\n\nIt was discovered that the USB Virtual Host Controller Interface (VHCI)\ndriver in the Linux kernel contained an information disclosure\nvulnerability. A physically proximate attacker could use this to expose\nsensitive information (kernel memory). (CVE-2017-16911)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not validate endpoint numbers. A remote attacker could use this to\ncause a denial of service (system crash). (CVE-2017-16912)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not properly validate CMD_SUBMIT packets. A remote attacker could use\nthis to cause a denial of service (excessive memory consumption).\n(CVE-2017-16913)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ncontained a NULL pointer dereference error. A remote attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-16914)\n\nIt was discovered that the core USB subsystem in the Linux kernel did not\nvalidate the number of configurations and interfaces in a device. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-17558)\n\nIt was discovered that an integer overflow existed in the perf subsystem of\nthe Linux kernel. A local attacker could use this to cause a denial of\nservice (system crash). (CVE-2017-18255)\n\nIt was discovered that the keyring subsystem in the Linux kernel did not\nproperly prevent a user from creating keyrings for other users. A local\nattacker could use this cause a denial of service or expose sensitive\ninformation. (CVE-2017-18270)\n\nAndy Lutomirski and Willy Tarreau discovered that the KVM implementation in\nthe Linux kernel did not properly emulate instructions on the SS segment\nregister. A local attacker in a guest virtual machine could use this to\ncause a denial of service (guest OS crash) or possibly gain administrative\nprivileges in the guest OS. (CVE-2017-2583)\n\nDmitry Vyukov discovered that the KVM implementation in the Linux kernel\nimproperly emulated certain instructions. A local attacker could use this\nto obtain sensitive information (kernel memory). (CVE-2017-2584)\n\nIt was discovered that the KLSI KL5KUSB105 serial-to-USB device driver in\nthe Linux kernel did not properly initialize memory related to logging. A\nlocal attacker could use this to expose sensitive information (kernel\nmemory). (CVE-2017-5549)\n\nAndrey Konovalov discovered an out-of-bounds access in the IPv6 Generic\nRouting Encapsulation (GRE) tunneling implementation in the Linux kernel.\nAn attacker could use this to possibly expose sensitive information.\n(CVE-2017-5897)\n\nAndrey Konovalov discovered that the LLC subsytem in the Linux kernel did\nnot properly set up a destructor in certain situations. A local attacker\ncould use this to cause a denial of service (system crash). (CVE-2017-6345)\n\nDmitry Vyukov discovered race conditions in the Infrared (IrDA) subsystem\nin the Linux kernel. A local attacker could use this to cause a denial of\nservice (deadlock). (CVE-2017-6348)\n\nAndy Lutomirski discovered that the KVM implementation in the Linux kernel\nwas vulnerable to a debug exception error when single-stepping through a\nsyscall. A local attacker in a non-Linux guest vm could possibly use this\nto gain administrative privileges in the guest vm. (CVE-2017-7518)\n\nTuomas Haanpää and Ari Kauppi discovered that the NFSv2 and NFSv3 server\nimplementations in the Linux kernel did not properly handle certain long\nRPC replies. A remote attacker could use this to cause a denial of service\n(system crash). (CVE-2017-7645)\n\nPengfei Wang discovered that a race condition existed in the NXP SAA7164 TV\nDecoder driver for the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-8831)\n\nPengfei Wang discovered that the Turtle Beach MultiSound audio device\ndriver in the Linux kernel contained race conditions when fetching from the\nring-buffer. A local attacker could use this to cause a denial of service\n(infinite loop). (CVE-2017-9984, CVE-2017-9985)\n\nIt was discovered that the wait4() system call in the Linux kernel did not\nproperly validate its arguments in some situations. A local attacker could\npossibly use this to cause a denial of service. (CVE-2018-10087)\n\nIt was discovered that the kill() system call implementation in the Linux\nkernel did not properly validate its arguments in some situations. A local\nattacker could possibly use this to cause a denial of service.\n(CVE-2018-10124)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly validate meta-data information. An attacker could\nuse this to construct a malicious xfs image that, when mounted, could cause\na denial of service (system crash). (CVE-2018-10323)\n\nZhong Jiang discovered that a use-after-free vulnerability existed in the\nNUMA memory policy implementation in the Linux kernel. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2018-10675)\n\nWen Xu discovered that a buffer overflow existed in the ext4 filesystem\nimplementation in the Linux kernel. An attacker could use this to construct\na malicious ext4 image that, when mounted, could cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2018-10877)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly keep meta-data information consistent in some\nsituations. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10881)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly handle corrupted meta data in some situations. An\nattacker could use this to specially craft an ext4 filesystem that caused\na denial of service (system crash) when mounted. (CVE-2018-1092)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly handle corrupted meta data in some situations. An\nattacker could use this to specially craft an ext4 filesystem that caused a\ndenial of service (system crash) when mounted. (CVE-2018-1093)\n\nIt was discovered that the cdrom driver in the Linux kernel contained an\nincorrect bounds check. A local attacker could use this to expose sensitive\ninformation (kernel memory). (CVE-2018-10940)\n\nShankara Pailoor discovered that the JFS filesystem implementation in the\nLinux kernel contained a buffer overflow when handling extended attributes.\nA local attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2018-12233)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly handle an error condition with a corrupted xfs\nimage. An attacker could use this to construct a malicious xfs image that,\nwhen mounted, could cause a denial of service (system crash).\n(CVE-2018-13094)\n\nIt was discovered that the Linux kernel did not properly handle setgid file\ncreation when performed by a non-member of the group. A local attacker\ncould use this to gain elevated privileges. (CVE-2018-13405)\n\nSilvio Cesare discovered that the generic VESA frame buffer driver in the\nLinux kernel contained an integer overflow. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-13406)\n\nDaniel Jiang discovered that a race condition existed in the ipv4 ping\nsocket implementation in the Linux kernel. A local privileged attacker\ncould use this to cause a denial of service (system crash). (CVE-2017-2671)\n\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-1000204)\n\nIt was discovered that a memory leak existed in the Serial Attached SCSI\n(SAS) implementation in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (memory exhaustion).\n(CVE-2018-10021)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-157.207","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-157-generic","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-generic-lpae","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-lowlatency","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc-e500","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc-e500mc","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc-smp","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc64-emb","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc64-smp","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-extra-3.13.0-157-generic","version":"3.13.0-157.207","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10208","CVE-2017-11472","CVE-2017-11473","CVE-2017-14991","CVE-2017-15649","CVE-2017-16526","CVE-2017-16527","CVE-2017-16529","CVE-2017-16531","CVE-2017-16532","CVE-2017-16533","CVE-2017-16535","CVE-2017-16536","CVE-2017-16537","CVE-2017-16538","CVE-2017-16643","CVE-2017-16644","CVE-2017-16645","CVE-2017-16650","CVE-2017-16911","CVE-2017-16912","CVE-2017-16913","CVE-2017-16914","CVE-2017-17558","CVE-2017-18255","CVE-2017-18270","CVE-2017-2583","CVE-2017-2584","CVE-2017-2671","CVE-2017-5549","CVE-2017-5897","CVE-2017-6345","CVE-2017-6348","CVE-2017-7518","CVE-2017-7645","CVE-2017-8831","CVE-2017-9984","CVE-2017-9985","CVE-2018-1000204","CVE-2018-10021","CVE-2018-10087","CVE-2018-10124","CVE-2018-10323","CVE-2018-10675","CVE-2018-10877","CVE-2018-10881","CVE-2018-1092","CVE-2018-1093","CVE-2018-10940","CVE-2018-12233","CVE-2018-13094","CVE-2018-13405","CVE-2018-13406"]}]},{"id":"CVE-2017-11472","published":"2017-07-20T00:00:00","updated_at":"2026-07-04T07:41:18.500475+00:00","description":"\nThe acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the\nLinux kernel before 4.12 does not flush the operand cache and causes a\nkernel stack dump, which allows local users to obtain sensitive information\nfrom kernel memory and bypass the KASLR protection mechanism (in the kernel\nthrough 4.9) via a crafted ACPI table.","ubuntu_description":"\nIt was discovered that an information disclosure vulnerability existed in\nthe ACPI implementation of the Linux kernel. A local attacker could use\nthis to expose sensitive information (kernel memory addresses).","notes":[],"codename":null,"priority":"low","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=3b2d69114fefa474fca542e51119036dceb4aa6f","https://github.com/acpica/acpica/commit/a23325b2e583556eae88ed3f764e457786bf4df6","https://github.com/torvalds/linux/commit/3b2d69114fefa474fca542e51119036dceb4aa6f","https://ubuntu.com/security/notices/USN-3619-1","https://ubuntu.com/security/notices/USN-3619-2","https://ubuntu.com/security/notices/USN-3754-1","https://www.cve.org/CVERecord?id=CVE-2017-11472"],"bugs":[""],"patches":{"linux":["break-fix: - 3b2d69114fefa474fca542e51119036dceb4aa6f"],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-azure-edge":[],"linux-hwe-5.4":[],"linux-hwe-5.15":[],"linux-hwe-6.8":[],"linux-aws-5.4":[],"linux-aws-5.15":[],"linux-aws-hwe":[],"linux-azure-4.15":[],"linux-azure-5.4":[],"linux-azure-5.15":[],"linux-azure-fde":[],"linux-azure-fde-5.15":[],"linux-bluefield":[],"linux-fips":[],"linux-aws-fips":[],"linux-azure-fips":[],"linux-gcp-fips":[],"linux-gcp-4.15":[],"linux-gcp-5.4":[],"linux-gcp-5.15":[],"linux-gkeop":[],"linux-gkeop-5.15":[],"linux-ibm":[],"linux-ibm-5.4":[],"linux-ibm-5.15":[],"linux-intel":[],"linux-intel-iotg":[],"linux-intel-iotg-5.15":[],"linux-iot":[],"linux-intel-iot-realtime":[],"linux-lowlatency":[],"linux-lowlatency-hwe-5.15":[],"linux-lowlatency-hwe-6.8":[],"linux-nvidia":[],"linux-nvidia-6.5":[],"linux-nvidia-6.8":[],"linux-nvidia-lowlatency":[],"linux-oracle":[],"linux-oracle-5.4":[],"linux-oracle-5.15":[],"linux-oem-6.8":[],"linux-raspi":[],"linux-raspi-5.4":[],"linux-raspi-realtime":[],"linux-realtime":[],"linux-riscv":[],"linux-riscv-5.15":[],"linux-riscv-6.8":[],"linux-xilinx-zynqmp":[],"linux-aws-6.8":[],"linux-gcp-6.8":[],"linux-oracle-6.8":[],"linux-azure-6.8":[],"linux-oem-6.11":[],"linux-hwe-6.11":[],"linux-hwe-6.14":[],"linux-aws-6.14":[],"linux-azure-6.11":[],"linux-azure-nvidia":[],"linux-gcp-6.11":[],"linux-gcp-6.14":[],"linux-ibm-6.8":[],"linux-lowlatency-hwe-6.11":[],"linux-nvidia-tegra":[],"linux-nvidia-tegra-5.15":[],"linux-nvidia-tegra-igx":[],"linux-oracle-6.14":[],"linux-oem-6.14":[],"linux-riscv-6.14":[],"linux-nvidia-6.11":[],"linux-realtime-6.8":[],"linux-realtime-6.14":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux-aws-fips","source":"https://ubuntu.com/security/cve?package=linux-aws-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-fips","debian":"https://tracker.debian.org/pkg/linux-aws-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1052.57+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-2000.4","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips2","component":null,"pocket":"fips"}]},{"name":"linux-azure-fips","source":"https://ubuntu.com/security/cve?package=linux-azure-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fips","debian":"https://tracker.debian.org/pkg/linux-azure-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1058.66+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1022.22+fips1","component":null,"pocket":"fips"}]},{"name":"linux-gcp-fips","source":"https://ubuntu.com/security/cve?package=linux-gcp-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-fips","debian":"https://tracker.debian.org/pkg/linux-gcp-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1048.56+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips1","component":null,"pocket":"fips"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.12.0-11.12","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-20.21","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life, was needed","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-16.19","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-157.207","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-119.143","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-20.21","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-9.12","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-19.19","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1007.7","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-1016.16","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1054.63","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1007.7","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1008.8","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1008.8","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-aws-5.15","source":"https://ubuntu.com/security/cve?package=linux-aws-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.15","debian":"https://tracker.debian.org/pkg/linux-aws-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.19~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-5.4","source":"https://ubuntu.com/security/cve?package=linux-aws-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.4","debian":"https://tracker.debian.org/pkg/linux-aws-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1020.20~18.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-6.14","source":"https://ubuntu.com/security/cve?package=linux-aws-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.14","debian":"https://tracker.debian.org/pkg/linux-aws-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-aws-6.8","source":"https://ubuntu.com/security/cve?package=linux-aws-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.8","debian":"https://tracker.debian.org/pkg/linux-aws-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1009.9~22.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1031.33~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1009.9","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-1005.7","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1009.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1006.6","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1006.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1082.92","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.8~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1022.22~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-6.11","source":"https://ubuntu.com/security/cve?package=linux-azure-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.11","debian":"https://tracker.debian.org/pkg/linux-azure-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-azure-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-azure-6.8","source":"https://ubuntu.com/security/cve?package=linux-azure-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.8","debian":"https://tracker.debian.org/pkg/linux-azure-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-edge","source":"https://ubuntu.com/security/cve?package=linux-azure-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-edge","debian":"https://tracker.debian.org/pkg/linux-azure-edge","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.18.0-1003.3~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde","source":"https://ubuntu.com/security/cve?package=linux-azure-fde","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde","debian":"https://tracker.debian.org/pkg/linux-azure-fde","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1019.24.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.14.0-1012.12","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1041.48","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-azure-fde-5.15]","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-fde-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]},{"name":"linux-azure-nvidia","source":"https://ubuntu.com/security/cve?package=linux-azure-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-nvidia","debian":"https://tracker.debian.org/pkg/linux-azure-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1013.14","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-bluefield","source":"https://ubuntu.com/security/cve?package=linux-bluefield","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-bluefield","debian":"https://tracker.debian.org/pkg/linux-bluefield","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1011.14","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-fips","source":"https://ubuntu.com/security/cve?package=linux-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fips","debian":"https://tracker.debian.org/pkg/linux-fips","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-92.102+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1017.22~recert1","component":null,"pocket":"fips"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1011.12","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.8","component":null,"pocket":"fips"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1006.6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-1002.5","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1006.6","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1003.3","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1071.81","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.15","debian":"https://tracker.debian.org/pkg/linux-gcp-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1006.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.4","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.4","debian":"https://tracker.debian.org/pkg/linux-gcp-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.11","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.11","debian":"https://tracker.debian.org/pkg/linux-gcp-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-gcp-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.14","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.14","debian":"https://tracker.debian.org/pkg/linux-gcp-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.8","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.8","debian":"https://tracker.debian.org/pkg/linux-gcp-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1010.11~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop","source":"https://ubuntu.com/security/cve?package=linux-gkeop","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop","debian":"https://tracker.debian.org/pkg/linux-gkeop","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1008.9","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop-5.15","source":"https://ubuntu.com/security/cve?package=linux-gkeop-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop-5.15","debian":"https://tracker.debian.org/pkg/linux-gkeop-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-32.35~16.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-37.41~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.14","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.14","debian":"https://tracker.debian.org/pkg/linux-hwe-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-24.24~24.04.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.13.0-26.29~16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.0.0-15.16~18.04.1","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm","source":"https://ubuntu.com/security/cve?package=linux-ibm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm","debian":"https://tracker.debian.org/pkg/linux-ibm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1009.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.15","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.15","debian":"https://tracker.debian.org/pkg/linux-ibm-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1034.37~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.4","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.4","debian":"https://tracker.debian.org/pkg/linux-ibm-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1010.11~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-6.8","source":"https://ubuntu.com/security/cve?package=linux-ibm-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-6.8","debian":"https://tracker.debian.org/pkg/linux-ibm-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-intel","source":"https://ubuntu.com/security/cve?package=linux-intel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel","debian":"https://tracker.debian.org/pkg/linux-intel","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iot-realtime","source":"https://ubuntu.com/security/cve?package=linux-intel-iot-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iot-realtime","debian":"https://tracker.debian.org/pkg/linux-intel-iot-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1021.26","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg","debian":"https://tracker.debian.org/pkg/linux-intel-iotg","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1004.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg-5.15","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg-5.15","debian":"https://tracker.debian.org/pkg/linux-intel-iotg-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-iot","source":"https://ubuntu.com/security/cve?package=linux-iot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-iot","debian":"https://tracker.debian.org/pkg/linux-iot","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1008.8","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1020.25","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1008.8","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency","debian":"https://tracker.debian.org/pkg/linux-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-22.22","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"replaced by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needs-triage]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-119.143~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [abandoned]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-nvidia","source":"https://ubuntu.com/security/cve?package=linux-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia","debian":"https://tracker.debian.org/pkg/linux-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1005.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.11","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.11","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1002.2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.5","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.5","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.5.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.8","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.8","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-nvidia-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-lowlatency","debian":"https://tracker.debian.org/pkg/linux-nvidia-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1009.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1013.13","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-5.15","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-5.15","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1009.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-igx","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-igx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-igx","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-igx","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1004.5","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1004.5","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.11","source":"https://ubuntu.com/security/cve?package=linux-oem-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.11","debian":"https://tracker.debian.org/pkg/linux-oem-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.14","source":"https://ubuntu.com/security/cve?package=linux-oem-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.14","debian":"https://tracker.debian.org/pkg/linux-oem-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1005.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-oem-6.8","source":"https://ubuntu.com/security/cve?package=linux-oem-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.8","debian":"https://tracker.debian.org/pkg/linux-oem-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1010.10","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1008.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1008.10~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1005.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1006.6","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.15","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.15","debian":"https://tracker.debian.org/pkg/linux-oracle-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.4","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.4","debian":"https://tracker.debian.org/pkg/linux-oracle-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.14","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.14","debian":"https://tracker.debian.org/pkg/linux-oracle-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.8","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.8","debian":"https://tracker.debian.org/pkg/linux-oracle-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1006.6~22.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1005.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1004.4","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1013.13~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi-realtime","source":"https://ubuntu.com/security/cve?package=linux-raspi-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-realtime","debian":"https://tracker.debian.org/pkg/linux-raspi-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.7.0-2001.1","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.13.0-1004.4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.15.0-1010.11","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1086.94","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-1005.5","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.15.0-1010.11","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [replaced by linux-raspi]","component":null,"pocket":"security"}]},{"name":"linux-realtime","source":"https://ubuntu.com/security/cve?package=linux-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime","debian":"https://tracker.debian.org/pkg/linux-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1006.6","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.1-1015.16","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.14","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.14","debian":"https://tracker.debian.org/pkg/linux-realtime-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1003.3~24.04.3","component":null,"pocket":"realtime"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.8","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.8","debian":"https://tracker.debian.org/pkg/linux-realtime-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.1-1004.4~22.04.1","component":null,"pocket":"realtime"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-riscv-5.8]","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.15","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.15","debian":"https://tracker.debian.org/pkg/linux-riscv-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.17~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.14","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.14","debian":"https://tracker.debian.org/pkg/linux-riscv-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-22.22.1~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.8","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.8","debian":"https://tracker.debian.org/pkg/linux-riscv-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"artful","status":"released","description":"4.4.0-1088.93","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1088.93","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-xilinx-zynqmp","source":"https://ubuntu.com/security/cve?package=linux-xilinx-zynqmp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-xilinx-zynqmp","debian":"https://tracker.debian.org/pkg/linux-xilinx-zynqmp","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1020.24","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1022.26","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.12~rc1, 4.4.114","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3619-2","USN-3619-1","USN-3754-1"],"notices":[{"id":"USN-3619-2","title":"Linux kernel (Xenial HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-04-05T20:14:49.308791","description":"USN-3619-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu\n14.04 LTS.\n\nJann Horn discovered that the Berkeley Packet Filter (BPF) implementation\nin the Linux kernel improperly performed sign extension in some situations.\nA local attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2017-16995)\n\nIt was discovered that a race condition leading to a use-after-free\nvulnerability existed in the ALSA PCM subsystem of the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2017-0861)\n\nIt was discovered that the KVM implementation in the Linux kernel allowed\npassthrough of the diagnostic I/O port 0x80. An attacker in a guest VM\ncould use this to cause a denial of service (system crash) in the host OS.\n(CVE-2017-1000407)\n\nIt was discovered that an information disclosure vulnerability existed in\nthe ACPI implementation of the Linux kernel. A local attacker could use\nthis to expose sensitive information (kernel memory addresses).\n(CVE-2017-11472)\n\nIt was discovered that a use-after-free vulnerability existed in the\nnetwork namespaces implementation in the Linux kernel. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2017-15129)\n\nIt was discovered that the Advanced Linux Sound Architecture (ALSA)\nsubsystem in the Linux kernel contained a use-after-free when handling\ndevice removal. A physically proximate attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2017-16528)\n\nAndrey Konovalov discovered that the usbtest device driver in the Linux\nkernel did not properly validate endpoint metadata. A physically proximate\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-16532)\n\nAndrey Konovalov discovered that the Conexant cx231xx USB video capture\ndriver in the Linux kernel did not properly validate interface descriptors.\nA physically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16536)\n\nAndrey Konovalov discovered that the SoundGraph iMON USB driver in the\nLinux kernel did not properly validate device metadata. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-16537)\n\nAndrey Konovalov discovered that the IMS Passenger Control Unit USB driver\nin the Linux kernel did not properly validate device descriptors. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16645)\n\nAndrey Konovalov discovered that the DiBcom DiB0700 USB DVB driver in the\nLinux kernel did not properly handle detach events. A physically proximate\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-16646)\n\nAndrey Konovalov discovered that the CDC USB Ethernet driver did not\nproperly validate device descriptors. A physically proximate attacker could\nuse this to cause a denial of service (system crash). (CVE-2017-16649)\n\nAndrey Konovalov discovered that the QMI WWAN USB driver did not properly\nvalidate device descriptors. A physically proximate attacker could use this\nto cause a denial of service (system crash). (CVE-2017-16650)\n\nIt was discovered that the USB Virtual Host Controller Interface (VHCI)\ndriver in the Linux kernel contained an information disclosure\nvulnerability. A physically proximate attacker could use this to expose\nsensitive information (kernel memory). (CVE-2017-16911)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not validate endpoint numbers. A remote attacker could use this to\ncause a denial of service (system crash). (CVE-2017-16912)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not properly validate CMD_SUBMIT packets. A remote attacker could use\nthis to cause a denial of service (excessive memory consumption).\n(CVE-2017-16913)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ncontained a NULL pointer dereference error. A remote attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-16914)\n\nIt was discovered that the HugeTLB component of the Linux kernel did not\nproperly handle holes in hugetlb ranges. A local attacker could use this to\nexpose sensitive information (kernel memory). (CVE-2017-16994)\n\nIt was discovered that the netfilter component of the Linux did not\nproperly restrict access to the connection tracking helpers list. A local\nattacker could use this to bypass intended access restrictions.\n(CVE-2017-17448)\n\nIt was discovered that the netlink subsystem in the Linux kernel did not\nproperly restrict observations of netlink messages to the appropriate net\nnamespace. A local attacker could use this to expose sensitive information\n(kernel netlink traffic). (CVE-2017-17449)\n\nIt was discovered that the netfilter passive OS fingerprinting (xt_osf)\nmodule did not properly perform access control checks. A local attacker\ncould improperly modify the system-wide OS fingerprint list.\n(CVE-2017-17450)\n\nIt was discovered that the core USB subsystem in the Linux kernel did not\nvalidate the number of configurations and interfaces in a device. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-17558)\n\nDmitry Vyukov discovered that the KVM implementation in the Linux kernel\ncontained an out-of-bounds read when handling memory-mapped I/O. A local\nattacker could use this to expose sensitive information. (CVE-2017-17741)\n\nIt was discovered that the Salsa20 encryption algorithm implementations in\nthe Linux kernel did not properly handle zero-length inputs. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-17805)\n\nIt was discovered that the HMAC implementation did not validate the state\nof the underlying cryptographic hash algorithm. A local attacker could use\nthis to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2017-17806)\n\nIt was discovered that the keyring implementation in the Linux kernel did\nnot properly check permissions when a key request was performed on a task's\ndefault keyring. A local attacker could use this to add keys to\nunauthorized keyrings. (CVE-2017-17807)\n\nAlexei Starovoitov discovered that the Berkeley Packet Filter (BPF)\nimplementation in the Linux kernel contained a branch-pruning logic issue\naround unreachable code. A local attacker could use this to cause a denial\nof service. (CVE-2017-17862)\n\nIt was discovered that the parallel cryptography component of the Linux\nkernel incorrectly freed kernel memory. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-18075)\n\nIt was discovered that a race condition existed in the Device Mapper\ncomponent of the Linux kernel. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2017-18203)\n\nIt was discovered that a race condition existed in the OCFS2 file system\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (kernel deadlock). (CVE-2017-18204)\n\nIt was discovered that an infinite loop could occur in the madvise(2)\nimplementation in the Linux kernel in certain circumstances. A local\nattacker could use this to cause a denial of service (system hang).\n(CVE-2017-18208)\n\nAndy Lutomirski discovered that the KVM implementation in the Linux kernel\nwas vulnerable to a debug exception error when single-stepping through a\nsyscall. A local attacker in a non-Linux guest vm could possibly use this\nto gain administrative privileges in the guest vm. (CVE-2017-7518)\n\nIt was discovered that the Broadcom NetXtremeII ethernet driver in the\nLinux kernel did not properly validate Generic Segment Offload (GSO) packet\nsizes. An attacker could use this to cause a denial of service (interface\nunavailability). (CVE-2018-1000026)\n\nIt was discovered that the Reliable Datagram Socket (RDS) implementation in\nthe Linux kernel contained an out-of-bounds write during RDMA page\nallocation. An attacker could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2018-5332)\n\nMohamed Ghannam discovered a null pointer dereference in the RDS (Reliable\nDatagram Sockets) protocol implementation of the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2018-5333)\n\n范龙飞 discovered that a race condition existed in loop block device\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5344)\n\nIt was discovered that an integer overflow error existed in the futex\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash). (CVE-2018-6927)\n\nIt was discovered that a NULL pointer dereference existed in the RDS\n(Reliable Datagram Sockets) protocol implementation in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2018-7492)\n\nIt was discovered that the Broadcom UniMAC MDIO bus controller driver in\nthe Linux kernel did not properly validate device resources. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2018-8043)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-aws","version":"4.4.0-1016.16","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-lts-xenial","version":"4.4.0-119.143~14.04.1","description":"Linux hardware enablement kernel from Xenial for Trusty","is_source":true},{"name":"linux-image-4.4.0-1016-aws","version":"4.4.0-1016.16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1016.16","pocket":"security"},{"name":"linux-image-4.4.0-119-generic","version":"4.4.0-119.143~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-119.143~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-119-generic-lpae","version":"4.4.0-119.143~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-119.143~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-119-lowlatency","version":"4.4.0-119.143~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-119.143~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-119-powerpc-e500mc","version":"4.4.0-119.143~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-119.143~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-119-powerpc-smp","version":"4.4.0-119.143~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-119.143~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-119-powerpc64-emb","version":"4.4.0-119.143~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-119.143~14.04.1","pocket":"security"},{"name":"linux-image-4.4.0-119-powerpc64-smp","version":"4.4.0-119.143~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-119.143~14.04.1","pocket":"security"},{"name":"linux-image-extra-4.4.0-119-generic","version":"4.4.0-119.143~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-119.143~14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-0861","CVE-2017-1000407","CVE-2017-11472","CVE-2017-15129","CVE-2017-16528","CVE-2017-16532","CVE-2017-16536","CVE-2017-16537","CVE-2017-16645","CVE-2017-16646","CVE-2017-16649","CVE-2017-16650","CVE-2017-16911","CVE-2017-16912","CVE-2017-16913","CVE-2017-16914","CVE-2017-16994","CVE-2017-16995","CVE-2017-17448","CVE-2017-17449","CVE-2017-17450","CVE-2017-17558","CVE-2017-17741","CVE-2017-17805","CVE-2017-17806","CVE-2017-17807","CVE-2017-17862","CVE-2017-18075","CVE-2017-18203","CVE-2017-18204","CVE-2017-18208","CVE-2017-7518","CVE-2018-1000026","CVE-2018-5332","CVE-2018-5333","CVE-2018-5344","CVE-2018-6927","CVE-2018-7492","CVE-2018-8043"]},{"id":"USN-3619-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-04-04T19:21:17.560003","description":"Jann Horn discovered that the Berkeley Packet Filter (BPF) implementation\nin the Linux kernel improperly performed sign extension in some situations.\nA local attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2017-16995)\n\nIt was discovered that a race condition leading to a use-after-free\nvulnerability existed in the ALSA PCM subsystem of the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2017-0861)\n\nIt was discovered that the KVM implementation in the Linux kernel allowed\npassthrough of the diagnostic I/O port 0x80. An attacker in a guest VM\ncould use this to cause a denial of service (system crash) in the host OS.\n(CVE-2017-1000407)\n\nIt was discovered that an information disclosure vulnerability existed in\nthe ACPI implementation of the Linux kernel. A local attacker could use\nthis to expose sensitive information (kernel memory addresses).\n(CVE-2017-11472)\n\nIt was discovered that a use-after-free vulnerability existed in the\nnetwork namespaces implementation in the Linux kernel. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2017-15129)\n\nIt was discovered that the Advanced Linux Sound Architecture (ALSA)\nsubsystem in the Linux kernel contained a use-after-free when handling\ndevice removal. A physically proximate attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2017-16528)\n\nAndrey Konovalov discovered that the usbtest device driver in the Linux\nkernel did not properly validate endpoint metadata. A physically proximate\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-16532)\n\nAndrey Konovalov discovered that the Conexant cx231xx USB video capture\ndriver in the Linux kernel did not properly validate interface descriptors.\nA physically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16536)\n\nAndrey Konovalov discovered that the SoundGraph iMON USB driver in the\nLinux kernel did not properly validate device metadata. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-16537)\n\nAndrey Konovalov discovered that the IMS Passenger Control Unit USB driver\nin the Linux kernel did not properly validate device descriptors. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16645)\n\nAndrey Konovalov discovered that the DiBcom DiB0700 USB DVB driver in the\nLinux kernel did not properly handle detach events. A physically proximate\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-16646)\n\nAndrey Konovalov discovered that the CDC USB Ethernet driver did not\nproperly validate device descriptors. A physically proximate attacker could\nuse this to cause a denial of service (system crash). (CVE-2017-16649)\n\nAndrey Konovalov discovered that the QMI WWAN USB driver did not properly\nvalidate device descriptors. A physically proximate attacker could use this\nto cause a denial of service (system crash). (CVE-2017-16650)\n\nIt was discovered that the USB Virtual Host Controller Interface (VHCI)\ndriver in the Linux kernel contained an information disclosure vulnerability.\nA physically proximate attacker could use this to expose sensitive\ninformation (kernel memory). (CVE-2017-16911)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not validate endpoint numbers. A remote attacker could use this to\ncause a denial of service (system crash). (CVE-2017-16912)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not properly validate CMD_SUBMIT packets. A remote attacker could use\nthis to cause a denial of service (excessive memory consumption).\n(CVE-2017-16913)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ncontained a NULL pointer dereference error. A remote attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-16914)\n\nIt was discovered that the HugeTLB component of the Linux kernel did not\nproperly handle holes in hugetlb ranges. A local attacker could use this to\nexpose sensitive information (kernel memory). (CVE-2017-16994)\n\nIt was discovered that the netfilter component of the Linux did not\nproperly restrict access to the connection tracking helpers list. A local\nattacker could use this to bypass intended access restrictions.\n(CVE-2017-17448)\n\nIt was discovered that the netlink subsystem in the Linux kernel did not\nproperly restrict observations of netlink messages to the appropriate net\nnamespace. A local attacker could use this to expose sensitive information\n(kernel netlink traffic). (CVE-2017-17449)\n\nIt was discovered that the netfilter passive OS fingerprinting (xt_osf)\nmodule did not properly perform access control checks. A local attacker\ncould improperly modify the system-wide OS fingerprint list.\n(CVE-2017-17450)\n\nIt was discovered that the core USB subsystem in the Linux kernel did not\nvalidate the number of configurations and interfaces in a device. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-17558)\n\nDmitry Vyukov discovered that the KVM implementation in the Linux kernel\ncontained an out-of-bounds read when handling memory-mapped I/O. A local\nattacker could use this to expose sensitive information. (CVE-2017-17741)\n\nIt was discovered that the Salsa20 encryption algorithm implementations in\nthe Linux kernel did not properly handle zero-length inputs. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-17805)\n\nIt was discovered that the HMAC implementation did not validate the state\nof the underlying cryptographic hash algorithm. A local attacker could use\nthis to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2017-17806)\n\nIt was discovered that the keyring implementation in the Linux kernel did\nnot properly check permissions when a key request was performed on a\ntask's default keyring. A local attacker could use this to add keys to\nunauthorized keyrings. (CVE-2017-17807)\n\nAlexei Starovoitov discovered that the Berkeley Packet Filter (BPF)\nimplementation in the Linux kernel contained a branch-pruning logic issue\naround unreachable code. A local attacker could use this to cause a denial\nof service. (CVE-2017-17862)\n\nIt was discovered that the parallel cryptography component of the Linux\nkernel incorrectly freed kernel memory. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-18075)\n\nIt was discovered that a race condition existed in the Device Mapper\ncomponent of the Linux kernel. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2017-18203)\n\nIt was discovered that a race condition existed in the OCFS2 file system\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (kernel deadlock). (CVE-2017-18204)\n\nIt was discovered that an infinite loop could occur in the madvise(2)\nimplementation in the Linux kernel in certain circumstances. A local\nattacker could use this to cause a denial of service (system hang).\n(CVE-2017-18208)\n\nAndy Lutomirski discovered that the KVM implementation in the Linux kernel\nwas vulnerable to a debug exception error when single-stepping through a\nsyscall. A local attacker in a non-Linux guest vm could possibly use this\nto gain administrative privileges in the guest vm. (CVE-2017-7518)\n\nIt was discovered that the Broadcom NetXtremeII ethernet driver in the\nLinux kernel did not properly validate Generic Segment Offload (GSO) packet\nsizes. An attacker could use this to cause a denial of service (interface\nunavailability). (CVE-2018-1000026)\n\nIt was discovered that the Reliable Datagram Socket (RDS)\nimplementation in the Linux kernel contained an out-of-bounds write\nduring RDMA page allocation. An attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2018-5332)\n\nMohamed Ghannam discovered a null pointer dereference in the RDS (Reliable\nDatagram Sockets) protocol implementation of the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2018-5333)\n\n范龙飞 discovered that a race condition existed in loop block device\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-5344)\n\nIt was discovered that an integer overflow error existed in the futex\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash). (CVE-2018-6927)\n\nIt was discovered that a NULL pointer dereference existed in the RDS\n(Reliable Datagram Sockets) protocol implementation in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2018-7492)\n\nIt was discovered that the Broadcom UniMAC MDIO bus controller driver in\nthe Linux kernel did not properly validate device resources. A local\nattacker could use this to cause a denial of service (system crash).\n(CVE-2018-8043)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux","version":"4.4.0-119.143","description":"Linux kernel","is_source":true},{"name":"linux-aws","version":"4.4.0-1054.63","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-kvm","version":"4.4.0-1020.25","description":"Linux kernel for cloud environments","is_source":true},{"name":"linux-raspi2","version":"4.4.0-1086.94","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-snapdragon","version":"4.4.0-1088.93","description":"Linux kernel for Snapdragon processors","is_source":true},{"name":"linux-image-4.4.0-1020-kvm","version":"4.4.0-1020.25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-kvm","version_link":"https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1020.25","pocket":"security"},{"name":"linux-image-4.4.0-1054-aws","version":"4.4.0-1054.63","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1054.63","pocket":"security"},{"name":"linux-image-4.4.0-1086-raspi2","version":"4.4.0-1086.94","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1086.94","pocket":"security"},{"name":"linux-image-4.4.0-1088-snapdragon","version":"4.4.0-1088.93","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon","version_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1088.93","pocket":"security"},{"name":"linux-image-4.4.0-119-generic","version":"4.4.0-119.143","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-119.143","pocket":"security"},{"name":"linux-image-4.4.0-119-generic-lpae","version":"4.4.0-119.143","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-119.143","pocket":"security"},{"name":"linux-image-4.4.0-119-lowlatency","version":"4.4.0-119.143","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-119.143","pocket":"security"},{"name":"linux-image-4.4.0-119-powerpc-e500mc","version":"4.4.0-119.143","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-119.143","pocket":"security"},{"name":"linux-image-4.4.0-119-powerpc-smp","version":"4.4.0-119.143","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-119.143","pocket":"security"},{"name":"linux-image-4.4.0-119-powerpc64-emb","version":"4.4.0-119.143","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-119.143","pocket":"security"},{"name":"linux-image-4.4.0-119-powerpc64-smp","version":"4.4.0-119.143","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-119.143","pocket":"security"},{"name":"linux-image-extra-4.4.0-119-generic","version":"4.4.0-119.143","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-119.143","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-0861","CVE-2017-1000407","CVE-2017-11472","CVE-2017-15129","CVE-2017-16528","CVE-2017-16532","CVE-2017-16536","CVE-2017-16537","CVE-2017-16645","CVE-2017-16646","CVE-2017-16649","CVE-2017-16650","CVE-2017-16911","CVE-2017-16912","CVE-2017-16913","CVE-2017-16914","CVE-2017-16994","CVE-2017-16995","CVE-2017-17448","CVE-2017-17449","CVE-2017-17450","CVE-2017-17558","CVE-2017-17741","CVE-2017-17805","CVE-2017-17806","CVE-2017-17807","CVE-2017-17862","CVE-2017-18075","CVE-2017-18203","CVE-2017-18204","CVE-2017-18208","CVE-2017-7518","CVE-2018-1000026","CVE-2018-5332","CVE-2018-5333","CVE-2018-5344","CVE-2018-6927","CVE-2018-7492","CVE-2018-8043"]},{"id":"USN-3754-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2018-08-24T00:38:00.274205","description":"Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel\ndid not properly validate meta block groups. An attacker with physical\naccess could use this to specially craft an ext4 image that causes a denial\nof service (system crash). (CVE-2016-10208)\n\nIt was discovered that an information disclosure vulnerability existed in\nthe ACPI implementation of the Linux kernel. A local attacker could use\nthis to expose sensitive information (kernel memory addresses).\n(CVE-2017-11472)\n\nIt was discovered that a buffer overflow existed in the ACPI table parsing\nimplementation in the Linux kernel. A local attacker could use this to\nconstruct a malicious ACPI table that, when loaded, caused a denial of\nservice (system crash) or possibly execute arbitrary code.\n(CVE-2017-11473)\n\nIt was discovered that the generic SCSI driver in the Linux kernel did not\nproperly initialize data returned to user space in some situations. A local\nattacker could use this to expose sensitive information (kernel memory).\n(CVE-2017-14991)\n\nIt was discovered that a race condition existed in the packet fanout\nimplementation in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-15649)\n\nAndrey Konovalov discovered that the Ultra Wide Band driver in the Linux\nkernel did not properly check for an error condition. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-16526)\n\nAndrey Konovalov discovered that the ALSA subsystem in the Linux kernel\ncontained a use-after-free vulnerability. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-16527)\n\nAndrey Konovalov discovered that the ALSA subsystem in the Linux kernel did\nnot properly validate USB audio buffer descriptors. A physically proximate\nattacker could use this cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2017-16529)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB interface association descriptors. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-16531)\n\nAndrey Konovalov discovered that the usbtest device driver in the Linux\nkernel did not properly validate endpoint metadata. A physically proximate\nattacker could use this to cause a denial of service (system crash).\n(CVE-2017-16532)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB HID descriptors. A physically proximate attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2017-16533)\n\nAndrey Konovalov discovered that the USB subsystem in the Linux kernel did\nnot properly validate USB BOS metadata. A physically proximate attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2017-16535)\n\nAndrey Konovalov discovered that the Conexant cx231xx USB video capture\ndriver in the Linux kernel did not properly validate interface descriptors.\nA physically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16536)\n\nAndrey Konovalov discovered that the SoundGraph iMON USB driver in the\nLinux kernel did not properly validate device metadata. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-16537)\n\nIt was discovered that the DM04/QQBOX USB driver in the Linux kernel did\nnot properly handle device attachment and warm-start. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-16538)\n\nAndrey Konovalov discovered an out-of-bounds read in the GTCO digitizer USB\ndriver for the Linux kernel. A physically proximate attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-16643)\n\nAndrey Konovalov discovered that the video4linux driver for Hauppauge HD\nPVR USB devices in the Linux kernel did not properly handle some error\nconditions. A physically proximate attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2017-16644)\n\nAndrey Konovalov discovered that the IMS Passenger Control Unit USB driver\nin the Linux kernel did not properly validate device descriptors. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-16645)\n\nAndrey Konovalov discovered that the QMI WWAN USB driver did not properly\nvalidate device descriptors. A physically proximate attacker could use this\nto cause a denial of service (system crash). (CVE-2017-16650)\n\nIt was discovered that the USB Virtual Host Controller Interface (VHCI)\ndriver in the Linux kernel contained an information disclosure\nvulnerability. A physically proximate attacker could use this to expose\nsensitive information (kernel memory). (CVE-2017-16911)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not validate endpoint numbers. A remote attacker could use this to\ncause a denial of service (system crash). (CVE-2017-16912)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ndid not properly validate CMD_SUBMIT packets. A remote attacker could use\nthis to cause a denial of service (excessive memory consumption).\n(CVE-2017-16913)\n\nIt was discovered that the USB over IP implementation in the Linux kernel\ncontained a NULL pointer dereference error. A remote attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-16914)\n\nIt was discovered that the core USB subsystem in the Linux kernel did not\nvalidate the number of configurations and interfaces in a device. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash). (CVE-2017-17558)\n\nIt was discovered that an integer overflow existed in the perf subsystem of\nthe Linux kernel. A local attacker could use this to cause a denial of\nservice (system crash). (CVE-2017-18255)\n\nIt was discovered that the keyring subsystem in the Linux kernel did not\nproperly prevent a user from creating keyrings for other users. A local\nattacker could use this cause a denial of service or expose sensitive\ninformation. (CVE-2017-18270)\n\nAndy Lutomirski and Willy Tarreau discovered that the KVM implementation in\nthe Linux kernel did not properly emulate instructions on the SS segment\nregister. A local attacker in a guest virtual machine could use this to\ncause a denial of service (guest OS crash) or possibly gain administrative\nprivileges in the guest OS. (CVE-2017-2583)\n\nDmitry Vyukov discovered that the KVM implementation in the Linux kernel\nimproperly emulated certain instructions. A local attacker could use this\nto obtain sensitive information (kernel memory). (CVE-2017-2584)\n\nIt was discovered that the KLSI KL5KUSB105 serial-to-USB device driver in\nthe Linux kernel did not properly initialize memory related to logging. A\nlocal attacker could use this to expose sensitive information (kernel\nmemory). (CVE-2017-5549)\n\nAndrey Konovalov discovered an out-of-bounds access in the IPv6 Generic\nRouting Encapsulation (GRE) tunneling implementation in the Linux kernel.\nAn attacker could use this to possibly expose sensitive information.\n(CVE-2017-5897)\n\nAndrey Konovalov discovered that the LLC subsytem in the Linux kernel did\nnot properly set up a destructor in certain situations. A local attacker\ncould use this to cause a denial of service (system crash). (CVE-2017-6345)\n\nDmitry Vyukov discovered race conditions in the Infrared (IrDA) subsystem\nin the Linux kernel. A local attacker could use this to cause a denial of\nservice (deadlock). (CVE-2017-6348)\n\nAndy Lutomirski discovered that the KVM implementation in the Linux kernel\nwas vulnerable to a debug exception error when single-stepping through a\nsyscall. A local attacker in a non-Linux guest vm could possibly use this\nto gain administrative privileges in the guest vm. (CVE-2017-7518)\n\nTuomas Haanpää and Ari Kauppi discovered that the NFSv2 and NFSv3 server\nimplementations in the Linux kernel did not properly handle certain long\nRPC replies. A remote attacker could use this to cause a denial of service\n(system crash). (CVE-2017-7645)\n\nPengfei Wang discovered that a race condition existed in the NXP SAA7164 TV\nDecoder driver for the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-8831)\n\nPengfei Wang discovered that the Turtle Beach MultiSound audio device\ndriver in the Linux kernel contained race conditions when fetching from the\nring-buffer. A local attacker could use this to cause a denial of service\n(infinite loop). (CVE-2017-9984, CVE-2017-9985)\n\nIt was discovered that the wait4() system call in the Linux kernel did not\nproperly validate its arguments in some situations. A local attacker could\npossibly use this to cause a denial of service. (CVE-2018-10087)\n\nIt was discovered that the kill() system call implementation in the Linux\nkernel did not properly validate its arguments in some situations. A local\nattacker could possibly use this to cause a denial of service.\n(CVE-2018-10124)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly validate meta-data information. An attacker could\nuse this to construct a malicious xfs image that, when mounted, could cause\na denial of service (system crash). (CVE-2018-10323)\n\nZhong Jiang discovered that a use-after-free vulnerability existed in the\nNUMA memory policy implementation in the Linux kernel. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2018-10675)\n\nWen Xu discovered that a buffer overflow existed in the ext4 filesystem\nimplementation in the Linux kernel. An attacker could use this to construct\na malicious ext4 image that, when mounted, could cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2018-10877)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly keep meta-data information consistent in some\nsituations. An attacker could use this to construct a malicious ext4 image\nthat, when mounted, could cause a denial of service (system crash).\n(CVE-2018-10881)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly handle corrupted meta data in some situations. An\nattacker could use this to specially craft an ext4 filesystem that caused\na denial of service (system crash) when mounted. (CVE-2018-1092)\n\nWen Xu discovered that the ext4 filesystem implementation in the Linux\nkernel did not properly handle corrupted meta data in some situations. An\nattacker could use this to specially craft an ext4 filesystem that caused a\ndenial of service (system crash) when mounted. (CVE-2018-1093)\n\nIt was discovered that the cdrom driver in the Linux kernel contained an\nincorrect bounds check. A local attacker could use this to expose sensitive\ninformation (kernel memory). (CVE-2018-10940)\n\nShankara Pailoor discovered that the JFS filesystem implementation in the\nLinux kernel contained a buffer overflow when handling extended attributes.\nA local attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2018-12233)\n\nWen Xu discovered that the XFS filesystem implementation in the Linux\nkernel did not properly handle an error condition with a corrupted xfs\nimage. An attacker could use this to construct a malicious xfs image that,\nwhen mounted, could cause a denial of service (system crash).\n(CVE-2018-13094)\n\nIt was discovered that the Linux kernel did not properly handle setgid file\ncreation when performed by a non-member of the group. A local attacker\ncould use this to gain elevated privileges. (CVE-2018-13405)\n\nSilvio Cesare discovered that the generic VESA frame buffer driver in the\nLinux kernel contained an integer overflow. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2018-13406)\n\nDaniel Jiang discovered that a race condition existed in the ipv4 ping\nsocket implementation in the Linux kernel. A local privileged attacker\ncould use this to cause a denial of service (system crash). (CVE-2017-2671)\n\nIt was discovered that an information leak existed in the generic SCSI\ndriver in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2018-1000204)\n\nIt was discovered that a memory leak existed in the Serial Attached SCSI\n(SAS) implementation in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (memory exhaustion).\n(CVE-2018-10021)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-157.207","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-157-generic","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-generic-lpae","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-lowlatency","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc-e500","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc-e500mc","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc-smp","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc64-emb","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-3.13.0-157-powerpc64-smp","version":"3.13.0-157.207","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"},{"name":"linux-image-extra-3.13.0-157-generic","version":"3.13.0-157.207","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-157.207","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10208","CVE-2017-11472","CVE-2017-11473","CVE-2017-14991","CVE-2017-15649","CVE-2017-16526","CVE-2017-16527","CVE-2017-16529","CVE-2017-16531","CVE-2017-16532","CVE-2017-16533","CVE-2017-16535","CVE-2017-16536","CVE-2017-16537","CVE-2017-16538","CVE-2017-16643","CVE-2017-16644","CVE-2017-16645","CVE-2017-16650","CVE-2017-16911","CVE-2017-16912","CVE-2017-16913","CVE-2017-16914","CVE-2017-17558","CVE-2017-18255","CVE-2017-18270","CVE-2017-2583","CVE-2017-2584","CVE-2017-2671","CVE-2017-5549","CVE-2017-5897","CVE-2017-6345","CVE-2017-6348","CVE-2017-7518","CVE-2017-7645","CVE-2017-8831","CVE-2017-9984","CVE-2017-9985","CVE-2018-1000204","CVE-2018-10021","CVE-2018-10087","CVE-2018-10124","CVE-2018-10323","CVE-2018-10675","CVE-2018-10877","CVE-2018-10881","CVE-2018-1092","CVE-2018-1093","CVE-2018-10940","CVE-2018-12233","CVE-2018-13094","CVE-2018-13405","CVE-2018-13406"]}]},{"id":"CVE-2017-10243","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:24.136139+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: JAX-WS). Supported versions that are affected are\nJava SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit:\nR28.3.14. Easily exploitable vulnerability allows unauthenticated attacker\nwith network access via multiple protocols to compromise Java SE, Java SE\nEmbedded, JRockit. Successful attacks of this vulnerability can result in\nunauthorized read access to a subset of Java SE, Java SE Embedded, JRockit\naccessible data and unauthorized ability to cause a partial denial of\nservice (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This\nvulnerability can be exploited through sandboxed Java Web Start\napplications and sandboxed Java applets. It can also be exploited by\nsupplying data to APIs in the specified Component without using sandboxed\nJava Web Start applications or sandboxed Java applets, such as through a\nweb service. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability\nimpacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).","ubuntu_description":"\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10243"],"bugs":[""],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jaxws/rev/65d3b0e44551"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10198","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:18.867465+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: Security). Supported versions that are affected are\nJava SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit:\nR28.3.14. Difficult to exploit vulnerability allows unauthenticated\nattacker with network access via multiple protocols to compromise Java SE,\nJava SE Embedded, JRockit. While the vulnerability is in Java SE, Java SE\nEmbedded, JRockit, attacks may significantly impact additional products.\nSuccessful attacks of this vulnerability can result in unauthorized access\nto critical data or complete access to all Java SE, Java SE Embedded,\nJRockit accessible data. Note: This vulnerability can be exploited through\nsandboxed Java Web Start applications and sandboxed Java applets. It can\nalso be exploited by supplying data to APIs in the specified Component\nwithout using sandboxed Java Web Start applications or sandboxed Java\napplets, such as through a web service. CVSS 3.0 Base Score 6.8\n(Confidentiality impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N).","ubuntu_description":"\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions.","notes":[],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://www.cve.org/CVERecord?id=CVE-2017-10198"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1472320"],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/276269460238"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3366-1"],"notices":[{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10193","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:18.867465+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded component of Oracle Java SE\n(subcomponent: Security). Supported versions that are affected are Java SE:\n6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit\nvulnerability allows unauthenticated attacker with network access via\nmultiple protocols to compromise Java SE, Java SE Embedded. Successful\nattacks require human interaction from a person other than the attacker.\nSuccessful attacks of this vulnerability can result in unauthorized read\naccess to a subset of Java SE, Java SE Embedded accessible data. Note: This\nvulnerability applies to Java deployments, typically in clients running\nsandboxed Java Web Start applications or sandboxed Java applets, that load\nand run untrusted code (e.g., code that comes from the internet) and rely\non the Java sandbox for security. This vulnerability does not apply to Java\ndeployments, typically in servers, that load and run only trusted code\n(e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1\n(Confidentiality impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).","ubuntu_description":"\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions.","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://www.cve.org/CVERecord?id=CVE-2017-10193"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1471715"],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/ca803888d467"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3366-1"],"notices":[{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10176","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:14.053102+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: Security). Supported versions that are affected are\nJava SE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14.\nEasily exploitable vulnerability allows unauthenticated attacker with\nnetwork access via multiple protocols to compromise Java SE, Java SE\nEmbedded, JRockit. Successful attacks of this vulnerability can result in\nunauthorized access to critical data or complete access to all Java SE,\nJava SE Embedded, JRockit accessible data. Note: This vulnerability can be\nexploited through sandboxed Java Web Start applications and sandboxed Java\napplets. It can also be exploited by supplying data to APIs in the\nspecified Component without using sandboxed Java Web Start applications or\nsandboxed Java applets, such as through a web service. CVSS 3.0 Base Score\n7.5 (Confidentiality impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","ubuntu_description":"\nIt was discovered that the Elliptic Curve (EC) implementation in\nOpenJDK did not properly compute certain elliptic curve points. An\nattacker could use this to expose sensitive information.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10176"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1472476"],"patches":{"openjdk-7":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/d99101781d7e"]},"tags":{},"packages":[{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10135","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:14.053102+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: JCE). Supported versions that are affected are Java\nSE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14.\nDifficult to exploit vulnerability allows unauthenticated attacker with\nnetwork access via multiple protocols to compromise Java SE, Java SE\nEmbedded, JRockit. Successful attacks of this vulnerability can result in\nunauthorized access to critical data or complete access to all Java SE,\nJava SE Embedded, JRockit accessible data. Note: This vulnerability can be\nexploited through sandboxed Java Web Start applications and sandboxed Java\napplets. It can also be exploited by supplying data to APIs in the\nspecified Component without using sandboxed Java Web Start applications or\nsandboxed Java applets, such as through a web service. CVSS 3.0 Base Score\n5.9 (Confidentiality impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).","ubuntu_description":"\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information.","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10135"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1471871"],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/079cd6c5de27"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10118","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:14.053102+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: JCE). Supported versions that are affected are Java\nSE: 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily\nexploitable vulnerability allows unauthenticated attacker with network\naccess via multiple protocols to compromise Java SE, Java SE Embedded,\nJRockit. Successful attacks of this vulnerability can result in\nunauthorized access to critical data or complete access to all Java SE,\nJava SE Embedded, JRockit accessible data. Note: This vulnerability can be\nexploited through sandboxed Java Web Start applications and sandboxed Java\napplets. It can also be exploited by supplying data to APIs in the\nspecified Component without using sandboxed Java Web Start applications or\nsandboxed Java applets, such as through a web service. CVSS 3.0 Base Score\n7.5 (Confidentiality impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","ubuntu_description":"\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10118"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1472470"],"patches":{"openjdk-7":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/996632997de8"]},"tags":{},"packages":[{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10116","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:14.053102+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: Security). Supported versions that are affected are\nJava SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit:\nR28.3.14. Difficult to exploit vulnerability allows unauthenticated\nattacker with network access via multiple protocols to compromise Java SE,\nJava SE Embedded, JRockit. Successful attacks require human interaction\nfrom a person other than the attacker and while the vulnerability is in\nJava SE, Java SE Embedded, JRockit, attacks may significantly impact\nadditional products. Successful attacks of this vulnerability can result in\ntakeover of Java SE, Java SE Embedded, JRockit. Note: This vulnerability\ncan be exploited through sandboxed Java Web Start applications and\nsandboxed Java applets. It can also be exploited by supplying data to APIs\nin the specified Component without using sandboxed Java Web Start\napplications or sandboxed Java applets, such as through a web service. CVSS\n3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).\nCVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this\nto specially craft an LDAP referral URL that exposes sensitive\ninformation or bypass access restrictions.","notes":[],"codename":null,"priority":"medium","cvss3":8.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10116"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1471738"],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/73dd1557f0ef"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10115","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:14.053102+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: JCE). Supported versions that are affected are Java\nSE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14.\nEasily exploitable vulnerability allows unauthenticated attacker with\nnetwork access via multiple protocols to compromise Java SE, Java SE\nEmbedded, JRockit. Successful attacks of this vulnerability can result in\nunauthorized access to critical data or complete access to all Java SE,\nJava SE Embedded, JRockit accessible data. Note: This vulnerability can be\nexploited through sandboxed Java Web Start applications and sandboxed Java\napplets. It can also be exploited by supplying data to APIs in the\nspecified Component without using sandboxed Java Web Start applications or\nsandboxed Java applets, such as through a web service. CVSS 3.0 Base Score\n7.5 (Confidentiality impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).","ubuntu_description":"\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information.","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10115"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1471851"],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/3c8ea47635b6"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10111","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:14.053102+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded component of Oracle Java SE\n(subcomponent: Libraries). The supported version that is affected is Java\nSE: 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows\nunauthenticated attacker with network access via multiple protocols to\ncompromise Java SE, Java SE Embedded. Successful attacks require human\ninteraction from a person other than the attacker and while the\nvulnerability is in Java SE, Java SE Embedded, attacks may significantly\nimpact additional products. Successful attacks of this vulnerability can\nresult in takeover of Java SE, Java SE Embedded. Note: This vulnerability\napplies to Java deployments, typically in clients running sandboxed Java\nWeb Start applications or sandboxed Java applets, that load and run\nuntrusted code (e.g., code that comes from the internet) and rely on the\nJava sandbox for security. This vulnerability does not apply to Java\ndeployments, typically in servers, that load and run only trusted code\n(e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6\n(Confidentiality, Integrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","https://ubuntu.com/security/notices/USN-3366-1","https://www.cve.org/CVERecord?id=CVE-2017-10111"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1471526","https://bugs.openjdk.java.net/browse/JDK-8184119"],"patches":{"openjdk-9":[],"openjdk-8":[]},"tags":{},"packages":[{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3366-1"],"notices":[{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10110","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:08.322944+00:00","description":"\nVulnerability in the Java SE component of Oracle Java SE (subcomponent:\nAWT). Supported versions that are affected are Java SE: 6u151, 7u141 and\n8u131. Easily exploitable vulnerability allows unauthenticated attacker\nwith network access via multiple protocols to compromise Java SE.\nSuccessful attacks require human interaction from a person other than the\nattacker and while the vulnerability is in Java SE, attacks may\nsignificantly impact additional products. Successful attacks of this\nvulnerability can result in takeover of Java SE. Note: This vulnerability\napplies to Java deployments, typically in clients running sandboxed Java\nWeb Start applications or sandboxed Java applets, that load and run\nuntrusted code (e.g., code that comes from the internet) and rely on the\nJava sandbox for security. This vulnerability does not apply to Java\ndeployments, typically in servers, that load and run only trusted code\n(e.g., code installed by an administrator). CVSS 3.0 Base Score 9.6\n(Confidentiality, Integrity and Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions","notes":[],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10110"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1471523"],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/78a83e6e0fe8"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10109","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:08.322944+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: Serialization). Supported versions that are affected\nare Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit:\nR28.3.14. Easily exploitable vulnerability allows unauthenticated attacker\nwith network access via multiple protocols to compromise Java SE, Java SE\nEmbedded, JRockit. Successful attacks of this vulnerability can result in\nunauthorized ability to cause a partial denial of service (partial DOS) of\nJava SE, Java SE Embedded, JRockit. Note: This vulnerability applies to\nJava deployments, typically in clients running sandboxed Java Web Start\napplications or sandboxed Java applets, that load and run untrusted code\n(e.g., code that comes from the internet) and rely on the Java sandbox for\nsecurity. This vulnerability does not apply to Java deployments, typically\nin servers, that load and run only trusted code (e.g., code installed by an\nadministrator). CVSS 3.0 Base Score 5.3 (Availability impacts). CVSS\nVector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","ubuntu_description":"\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption).","notes":[],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10109"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1471670"],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/56e0ab47dbec"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10108","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:08.322944+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle\nJava SE (subcomponent: Serialization). Supported versions that are affected\nare Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit:\nR28.3.14. Easily exploitable vulnerability allows unauthenticated attacker\nwith network access via multiple protocols to compromise Java SE, Java SE\nEmbedded, JRockit. Successful attacks of this vulnerability can result in\nunauthorized ability to cause a partial denial of service (partial DOS) of\nJava SE, Java SE Embedded, JRockit. Note: This vulnerability can be\nexploited through sandboxed Java Web Start applications and sandboxed Java\napplets. It can also be exploited by supplying data to APIs in the\nspecified Component without using sandboxed Java Web Start applications or\nsandboxed Java applets, such as through a web service. CVSS 3.0 Base Score\n5.3 (Availability impacts). CVSS Vector:\n(CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).","ubuntu_description":"\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption).","notes":[],"codename":null,"priority":"low","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html#AppendixJAVA","http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10108"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1471888"],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/936085d9aff0"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]},{"id":"CVE-2017-10107","published":"2017-07-20T00:00:00","updated_at":"2025-08-25T22:19:08.322944+00:00","description":"\nVulnerability in the Java SE, Java SE Embedded component of Oracle Java SE\n(subcomponent: RMI). Supported versions that are affected are Java SE:\n6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable\nvulnerability allows unauthenticated attacker with network access via\nmultiple protocols to compromise Java SE, Java SE Embedded. Successful\nattacks require human interaction from a person other than the attacker and\nwhile the vulnerability is in Java SE, Java SE Embedded, attacks may\nsignificantly impact additional products. Successful attacks of this\nvulnerability can result in takeover of Java SE, Java SE Embedded. Note:\nThis vulnerability applies to Java deployments, typically in clients\nrunning sandboxed Java Web Start applications or sandboxed Java applets,\nthat load and run untrusted code (e.g., code that comes from the internet)\nand rely on the Java sandbox for security. This vulnerability does not\napply to Java deployments, typically in servers, that load and run only\ntrusted code (e.g., code installed by an administrator). CVSS 3.0 Base\nScore 9.6 (Confidentiality, Integrity and Availability impacts). CVSS\nVector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).","ubuntu_description":"\nIt was discovered that the Activation ID implementation in the\nRMI component of OpenJDK did not properly check access control\npermissions in some situations. An attacker could use this to\nspecially construct an untrusted Java application or applet that\ncould escape sandbox restrictions.","notes":[],"codename":null,"priority":"medium","cvss3":9.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.6,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.oracle.com/technetwork/security-advisory/cpujul2017verbose-3236625.html#JAVA","https://ubuntu.com/security/notices/USN-3366-1","https://ubuntu.com/security/notices/USN-3396-1","https://www.cve.org/CVERecord?id=CVE-2017-10107"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1471266"],"patches":{"openjdk-7":[],"openjdk-6":[],"openjdk-9":[],"openjdk-8":["upstream: http://hg.openjdk.java.net/jdk8u/jdk8u/jdk/rev/97ea41335486"]},"tags":{},"packages":[{"name":"openjdk-6","source":"https://ubuntu.com/security/cve?package=openjdk-6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-6","debian":"https://tracker.debian.org/pkg/openjdk-6","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"}]},{"name":"openjdk-7","source":"https://ubuntu.com/security/cve?package=openjdk-7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-7","debian":"https://tracker.debian.org/pkg/openjdk-7","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"7u151-2.6.11-0ubuntu1.14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"openjdk-8","source":"https://ubuntu.com/security/cve?package=openjdk-8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-8","debian":"https://tracker.debian.org/pkg/openjdk-8","statuses":[{"release_codename":"artful","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8u131-b11-2ubuntu1.16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8u131-b11-2ubuntu1.17.04.2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"8u141-b15-1","component":null,"pocket":"security"}]},{"name":"openjdk-9","source":"https://ubuntu.com/security/cve?package=openjdk-9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=openjdk-9","debian":"https://tracker.debian.org/pkg/openjdk-9","statuses":[{"release_codename":"artful","status":"not-affected","description":"9b181-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"9~b114-0ubuntu1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3396-1","USN-3366-1"],"notices":[{"id":"USN-3396-1","title":"OpenJDK 7 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 7.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-08-18T05:46:08.336586","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to specially\nconstruct a jpeg image file that when opened by a Java application would\ncause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly handle\narchives containing files missing digests. An attacker could use this to\nmodify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot component\nof OpenJDK when generating range check loop predicates. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat could escape sandbox restrictions and cause a denial of service or\npossibly execute arbitrary code. (CVE-2017-10074)\n\nIt was discovered that OpenJDK did not properly process parentheses in\nfunction signatures. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and possibly\nexecute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation in OpenJDK did\nnot perform access control checks in certain situations. An attacker could\nuse this to specially construct an untrusted Java application or applet\nthat escaped sandbox restrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in OpenJDK did not\nproperly perform access control checks in some situations. An attacker\ncould use this to specially construct an untrusted Java application or\napplet that could escape sandbox restrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the JAXP\ncomponent of OpenJDK did not properly perform access control checks. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly granted\naccess to some internal resolvers. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in OpenJDK\ndid not properly track references in some situations. A remote attacker\ncould possibly use this to execute arbitrary code. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions in\nsome situations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not properly\nbound memory allocation when de-serializing objects. An attacker could use\nthis to cause a denial of service (memory consumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not properly\nbound memory allocations when de-serializing object instances. An attacker\ncould use this to cause a denial of service (memory consumption).\n(CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this to\nspecially construct an untrusted Java application or applet that could\nescape sandbox restrictions (CVE-2017-10110)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information or\nbypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed in the\nECDSA implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability existed in\nthe PKCS#8 implementation in OpenJDK. An attacker could use this to expose\nsensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation in OpenJDK\ndid not properly compute certain elliptic curve points. An attacker could\nuse this to expose sensitive information. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML documents.\nAn attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"openjdk-7","version":"7u151-2.6.11-0ubuntu1.14.04.1","description":"Open Source Java implementation","is_source":true},{"name":"icedtea-7-jre-jamvm","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-demo","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-doc","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jdk","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-headless","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-lib","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-jre-zero","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-source","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"},{"name":"openjdk-7-tests","version":"7u151-2.6.11-0ubuntu1.14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-7","version_link":"https://launchpad.net/ubuntu/+source/openjdk-7/7u151-2.6.11-0ubuntu1.14.04.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10243"]},{"id":"USN-3366-1","title":"OpenJDK 8 vulnerabilities","summary":"Several security issues were fixed in OpenJDK 8.\n","instructions":"This update uses a new upstream release, which includes additional\nbug fixes. After a standard system update you need to restart any\nJava applications or applets to make all the necessary changes.\n","references":[],"published":"2017-07-26T20:42:50.943856","description":"It was discovered that the JPEGImageReader class in OpenJDK would\nincorrectly read unused image data. An attacker could use this to\nspecially construct a jpeg image file that when opened by a Java\napplication would cause a denial of service. (CVE-2017-10053)\n\nIt was discovered that the JAR verifier in OpenJDK did not properly\nhandle archives containing files missing digests. An attacker could\nuse this to modify the signed contents of a JAR file. (CVE-2017-10067)\n\nIt was discovered that integer overflows existed in the Hotspot\ncomponent of OpenJDK when generating range check loop predicates. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions\nand cause a denial of service or possibly execute arbitrary\ncode. (CVE-2017-10074)\n\nIt was discovered that the JavaScript Scripting component of OpenJDK\nincorrectly allowed access to Java APIs. An attacker could use this\nto specially craft JavaScript code to bypass access restrictions.\n(CVE-2017-10078)\n\nIt was discovered that OpenJDK did not properly process parentheses\nin function signatures. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10081)\n\nIt was discovered that the ThreadPoolExecutor class in OpenJDK did not\nproperly perform access control checks when cleaning up threads. An\nattacker could use this to specially construct an untrusted Java\napplication or applet that could escape sandbox restrictions and\npossibly execute arbitrary code. (CVE-2017-10087)\n\nIt was discovered that the ServiceRegistry implementation\nin OpenJDK did not perform access control checks in certain\nsituations. An attacker could use this to specially construct\nan untrusted Java application or applet that escaped sandbox\nrestrictions. (CVE-2017-10089)\n\nIt was discovered that the channel groups implementation in\nOpenJDK did not properly perform access control checks in some\nsituations. An attacker could use this to specially construct an\nuntrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10090)\n\nIt was discovered that the DTM exception handling code in the\nJAXP component of OpenJDK did not properly perform access control\nchecks. An attacker could use this to specially construct an untrusted\nJava application or applet that could escape sandbox restrictions.\n(CVE-2017-10096)\n\nIt was discovered that the JAXP component of OpenJDK incorrectly\ngranted access to some internal resolvers. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions. (CVE-2017-10101)\n\nIt was discovered that the Distributed Garbage Collector (DGC) in\nOpenJDK did not properly track references in some situations. A\nremote attacker could possibly use this to execute arbitrary\ncode. (CVE-2017-10102)\n\nIt was discovered that the Activation ID implementation in the RMI\ncomponent of OpenJDK did not properly check access control permissions\nin some situations. An attacker could use this to specially construct\nan untrusted Java application or applet that could escape sandbox\nrestrictions. (CVE-2017-10107)\n\nIt was discovered that the BasicAttribute class in OpenJDK did not\nproperly bound memory allocation when de-serializing objects. An\nattacker could use this to cause a denial of service (memory\nconsumption). (CVE-2017-10108)\n\nIt was discovered that the CodeSource class in OpenJDK did not\nproperly bound memory allocations when de-serializing object\ninstances. An attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-10109)\n\nIt was discovered that the AWT ImageWatched class in OpenJDK did not\nproperly perform access control checks, An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions (CVE-2017-10110)\n\nJackson Davis discovered that the LambdaFormEditor class in the\nLibraries component of OpenJDK did not correctly perform bounds checks\nin the permuteArgumentsForm() function. An attacker could use this\nto specially construct an untrusted Java application or applet that\ncould escape sandbox restrictions and possibly execute arbitrary\ncode. (CVE-2017-10111)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the DSA implementation in OpenJDK. An attacker could use this to\nexpose sensitive information. (CVE-2017-10115)\n\nIt was discovered that the LDAP implementation in OpenJDK incorrectly\nfollowed references to non-LDAP URLs. An attacker could use this to\nspecially craft an LDAP referral URL that exposes sensitive information\nor bypass access restrictions. (CVE-2017-10116)\n\nIt was discovered that a timing side-channel vulnerability existed\nin the ECDSA implementation in OpenJDK. An attacker could use this\nto expose sensitive information. (CVE-2017-10118)\n\nIlya Maykov discovered that a timing side-channel vulnerability\nexisted in the PKCS#8 implementation in OpenJDK. An attacker could\nuse this to expose sensitive information. (CVE-2017-10135)\n\nIt was discovered that the Elliptic Curve (EC) implementation\nin OpenJDK did not properly compute certain elliptic curve\npoints. An attacker could use this to expose sensitive\ninformation. (CVE-2017-10176)\n\nIt was discovered that OpenJDK did not properly restrict weak key\nsizes in some situations. An attacker could use this to specially\nconstruct an untrusted Java application or applet that could escape\nsandbox restrictions. (CVE-2017-10193)\n\nIt was discovered that OpenJDK did not properly enforce disabled\nalgorithm restrictions on X.509 certificate chains. An attacker\ncould use this to expose sensitive information or escape sandbox\nrestrictions. (CVE-2017-10198)\n\nIt was discovered that OpenJDK did not properly perform access control\nchecks when handling Web Service Definition Language (WSDL) XML\ndocuments. An attacker could use this to expose sensitive information.\n(CVE-2017-10243)\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.16.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-demo","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-doc","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-jamvm","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"},{"name":"openjdk-8-source","version":"8u131-b11-2ubuntu1.16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.16.04.2","pocket":"security"}],"zesty":[{"name":"openjdk-8","version":"8u131-b11-2ubuntu1.17.04.2","description":"Open Source Java implementation","is_source":true},{"name":"openjdk-8-jdk","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jdk-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-headless","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"},{"name":"openjdk-8-jre-zero","version":"8u131-b11-2ubuntu1.17.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/openjdk-8","version_link":"https://launchpad.net/ubuntu/+source/openjdk-8/8u131-b11-2ubuntu1.17.04.2"}]},"type":"USN","cves_ids":["CVE-2017-10053","CVE-2017-10067","CVE-2017-10074","CVE-2017-10078","CVE-2017-10081","CVE-2017-10087","CVE-2017-10089","CVE-2017-10090","CVE-2017-10096","CVE-2017-10101","CVE-2017-10102","CVE-2017-10107","CVE-2017-10108","CVE-2017-10109","CVE-2017-10110","CVE-2017-10111","CVE-2017-10115","CVE-2017-10116","CVE-2017-10118","CVE-2017-10135","CVE-2017-10176","CVE-2017-10193","CVE-2017-10198","CVE-2017-10243"]}]}],"offset":56220,"limit":20,"total_results":79316}