{"cves":[{"id":"CVE-2016-10130","published":"2017-03-24T15:59:00","updated_at":"2026-08-13T19:55:26.643143+00:00","description":"\nThe http_connect function in transports/http.c in libgit2 before 0.24.6 and\n0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof\nservers by leveraging clobbering of the error variable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/libgit2/libgit2/commit/9a64e62f0f20c9cf9b2e1609f037060eb2d8eb22","https://www.cve.org/CVERecord?id=CVE-2016-10130","https://ubuntu.com/security/notices/USN-8628-1"],"bugs":[""],"patches":{"libgit2":[]},"tags":{},"packages":[{"name":"libgit2","source":"https://ubuntu.com/security/cve?package=libgit2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgit2","debian":"https://tracker.debian.org/pkg/libgit2","statuses":[{"release_codename":"xenial","status":"released","description":"0.24.1-2ubuntu0.2+esm3","component":null,"pocket":"esm-apps-legacy"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.24.6, 0.25.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8628-1"],"notices":[{"id":"USN-8628-1","title":"libgit2 vulnerabilities","summary":"Several security issues were fixed in libgit2.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-12T19:13:07.070731","description":"It was discovered that libgit2 incorrectly handled the Git Smart Protocol.\nA remote attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 14.04\nLTS and Ubuntu 16.04 LTS. (CVE-2016-10128)\n\nIt was discovered that libgit2 incorrectly handled empty packet lines in\nthe Git Smart Protocol. A remote attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 16.04 LTS. (CVE-2016-10129)\n\nIt was discovered that libgit2 incorrectly handled error reporting in the\nHTTP transport. A remote attacker could possibly use this issue to spoof\nservers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130)\n\nIt was discovered that libgit2 incorrectly handled certain crafted \"ng\"\npackets. A remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,\nand Ubuntu 18.04 LTS. (CVE-2018-15501)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS. (CVE-2018-8098)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled submodule paths. A remote attacker could possibly use\nthis issue to write files outside the working tree. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 26.04 LTS. (CVE-2026-53584)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled delta object result-size headers. A remote attacker\ncould possibly use this issue to cause libgit2 to consume excessive memory,\nleading to a denial of service. (CVE-2026-53585)\n\nThai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects.\nA remote attacker could possibly use this issue to leak credentials to an\noffsite redirect target. This issue only affected Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n(CVE-2026-53586)\n\nIt was discovered that libgit2 incorrectly handled certain capability\nbuffers in the smart protocol. A remote attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 24.04\nLTS and Ubuntu 26.04 LTS. (CVE-2026-53587)","is_hidden":false,"release_packages":{"bionic":[{"name":"libgit2","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-26","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libgit2","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-28","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"libgit2","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.1","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-fixtures","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"libgit2","version":"1.7.2+ds-1ubuntu3.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.7","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-dev","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"}],"resolute":[{"name":"libgit2","version":"1.9.1+ds-1ubuntu1.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.9","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-dev","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"}],"trusty":[{"name":"libgit2","version":"0.19.0-2ubuntu0.4+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-0","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgit2-dev","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libgit2","version":"0.24.1-2ubuntu0.2+esm3","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-24","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libgit2-dev","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-53587","CVE-2016-10129","CVE-2016-10128","CVE-2018-8099","CVE-2018-15501","CVE-2016-10130","CVE-2018-8098","CVE-2026-53584","CVE-2026-53586","CVE-2026-53585"]}]},{"id":"CVE-2016-10129","published":"2017-03-24T15:59:00","updated_at":"2026-08-13T19:53:45.555927+00:00","description":"\nThe Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before\n0.25.1 allows remote attackers to cause a denial of service (NULL pointer\ndereference) via an empty packet line.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/libgit2/libgit2/commit/2fdef641fd0dd2828bd948234ae86de75221a11a","https://www.cve.org/CVERecord?id=CVE-2016-10129","https://ubuntu.com/security/notices/USN-8628-1"],"bugs":[""],"patches":{"libgit2":[]},"tags":{},"packages":[{"name":"libgit2","source":"https://ubuntu.com/security/cve?package=libgit2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgit2","debian":"https://tracker.debian.org/pkg/libgit2","statuses":[{"release_codename":"trusty","status":"released","description":"0.19.0-2ubuntu0.4+esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"0.24.1-2ubuntu0.2+esm3","component":null,"pocket":"esm-apps-legacy"},{"release_codename":"impish","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.24.6, 0.25.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8628-1"],"notices":[{"id":"USN-8628-1","title":"libgit2 vulnerabilities","summary":"Several security issues were fixed in libgit2.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-12T19:13:07.070731","description":"It was discovered that libgit2 incorrectly handled the Git Smart Protocol.\nA remote attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 14.04\nLTS and Ubuntu 16.04 LTS. (CVE-2016-10128)\n\nIt was discovered that libgit2 incorrectly handled empty packet lines in\nthe Git Smart Protocol. A remote attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 16.04 LTS. (CVE-2016-10129)\n\nIt was discovered that libgit2 incorrectly handled error reporting in the\nHTTP transport. A remote attacker could possibly use this issue to spoof\nservers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130)\n\nIt was discovered that libgit2 incorrectly handled certain crafted \"ng\"\npackets. A remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,\nand Ubuntu 18.04 LTS. (CVE-2018-15501)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS. (CVE-2018-8098)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled submodule paths. A remote attacker could possibly use\nthis issue to write files outside the working tree. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 26.04 LTS. (CVE-2026-53584)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled delta object result-size headers. A remote attacker\ncould possibly use this issue to cause libgit2 to consume excessive memory,\nleading to a denial of service. (CVE-2026-53585)\n\nThai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects.\nA remote attacker could possibly use this issue to leak credentials to an\noffsite redirect target. This issue only affected Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n(CVE-2026-53586)\n\nIt was discovered that libgit2 incorrectly handled certain capability\nbuffers in the smart protocol. A remote attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 24.04\nLTS and Ubuntu 26.04 LTS. (CVE-2026-53587)","is_hidden":false,"release_packages":{"bionic":[{"name":"libgit2","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-26","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libgit2","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-28","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"libgit2","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.1","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-fixtures","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"libgit2","version":"1.7.2+ds-1ubuntu3.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.7","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-dev","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"}],"resolute":[{"name":"libgit2","version":"1.9.1+ds-1ubuntu1.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.9","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-dev","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"}],"trusty":[{"name":"libgit2","version":"0.19.0-2ubuntu0.4+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-0","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgit2-dev","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libgit2","version":"0.24.1-2ubuntu0.2+esm3","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-24","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libgit2-dev","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-53587","CVE-2016-10129","CVE-2016-10128","CVE-2018-8099","CVE-2018-15501","CVE-2016-10130","CVE-2018-8098","CVE-2026-53584","CVE-2026-53586","CVE-2026-53585"]}]},{"id":"CVE-2016-10128","published":"2017-03-24T15:59:00","updated_at":"2026-08-13T19:52:59.966254+00:00","description":"\nBuffer overflow in the git_pkt_parse_line function in\ntransports/smart_pkt.c in the Git Smart Protocol support in libgit2 before\n0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified\nimpact via a crafted non-flush packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://github.com/libgit2/libgit2/commit/66e3774d279672ee51c3b54545a79d20d1ada834","https://www.cve.org/CVERecord?id=CVE-2016-10128","https://ubuntu.com/security/notices/USN-8628-1"],"bugs":[""],"patches":{"libgit2":[]},"tags":{},"packages":[{"name":"libgit2","source":"https://ubuntu.com/security/cve?package=libgit2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libgit2","debian":"https://tracker.debian.org/pkg/libgit2","statuses":[{"release_codename":"trusty","status":"released","description":"0.19.0-2ubuntu0.4+esm2","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"0.24.1-2ubuntu0.2+esm3","component":null,"pocket":"esm-apps-legacy"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.24.6, 0.25.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.26.0+dfsg.1-1.1build1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8628-1"],"notices":[{"id":"USN-8628-1","title":"libgit2 vulnerabilities","summary":"Several security issues were fixed in libgit2.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-12T19:13:07.070731","description":"It was discovered that libgit2 incorrectly handled the Git Smart Protocol.\nA remote attacker could possibly use this issue to cause a denial of\nservice or execute arbitrary code. This issue only affected Ubuntu 14.04\nLTS and Ubuntu 16.04 LTS. (CVE-2016-10128)\n\nIt was discovered that libgit2 incorrectly handled empty packet lines in\nthe Git Smart Protocol. A remote attacker could possibly use this issue\nto cause a denial of service. This issue only affected Ubuntu 14.04 LTS\nand Ubuntu 16.04 LTS. (CVE-2016-10129)\n\nIt was discovered that libgit2 incorrectly handled error reporting in the\nHTTP transport. A remote attacker could possibly use this issue to spoof\nservers. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10130)\n\nIt was discovered that libgit2 incorrectly handled certain crafted \"ng\"\npackets. A remote attacker could possibly use this issue to cause a denial\nof service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,\nand Ubuntu 18.04 LTS. (CVE-2018-15501)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n18.04 LTS. (CVE-2018-8098)\n\nKrishna Ram Prakash R and Vivek Parikh discovered that libgit2 incorrectly\nhandled certain repository index files. A local attacker could possibly use\nthis issue to cause a denial of service. This issue only affected Ubuntu\n14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2018-8099)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled submodule paths. A remote attacker could possibly use\nthis issue to write files outside the working tree. This issue only\naffected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and\nUbuntu 26.04 LTS. (CVE-2026-53584)\n\nMichał Majchrowicz and Marcin Wyczechowski discovered that libgit2\nincorrectly handled delta object result-size headers. A remote attacker\ncould possibly use this issue to cause libgit2 to consume excessive memory,\nleading to a denial of service. (CVE-2026-53585)\n\nThai Son Dinh discovered that libgit2 incorrectly handled HTTP redirects.\nA remote attacker could possibly use this issue to leak credentials to an\noffsite redirect target. This issue only affected Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.\n(CVE-2026-53586)\n\nIt was discovered that libgit2 incorrectly handled certain capability\nbuffers in the smart protocol. A remote attacker could possibly use this\nissue to cause a denial of service. This issue only affected Ubuntu 24.04\nLTS and Ubuntu 26.04 LTS. (CVE-2026-53587)","is_hidden":false,"release_packages":{"bionic":[{"name":"libgit2","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-26","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.26.0+dfsg.1-1.1ubuntu0.2+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"libgit2","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-28","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"0.28.4+dfsg.1-2ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"libgit2","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.1","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-dev","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"},{"name":"libgit2-fixtures","version":"1.1.0+dfsg.1-4.1ubuntu0.1+esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps"}],"noble":[{"name":"libgit2","version":"1.7.2+ds-1ubuntu3.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.7","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-dev","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.7.2+ds-1ubuntu3.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.7.2+ds-1ubuntu3.1","pocket":"security"}],"resolute":[{"name":"libgit2","version":"1.9.1+ds-1ubuntu1.1","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-1.9","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-dev","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"},{"name":"libgit2-fixtures","version":"1.9.1+ds-1ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":"https://launchpad.net/ubuntu/+source/libgit2/1.9.1+ds-1ubuntu1.1","pocket":"security"}],"trusty":[{"name":"libgit2","version":"0.19.0-2ubuntu0.4+esm2","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-0","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libgit2-dev","version":"0.19.0-2ubuntu0.4+esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"libgit2","version":"0.24.1-2ubuntu0.2+esm3","description":"Portable C implementation of the Git core methods library","is_source":true},{"name":"libgit2-24","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"},{"name":"libgit2-dev","version":"0.24.1-2ubuntu0.2+esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libgit2","version_link":null,"pocket":"esm-apps-legacy"}]},"type":"USN","cves_ids":["CVE-2026-53587","CVE-2016-10129","CVE-2016-10128","CVE-2018-8099","CVE-2018-15501","CVE-2016-10130","CVE-2018-8098","CVE-2026-53584","CVE-2026-53586","CVE-2026-53585"]}]},{"id":"CVE-2017-5644","published":"2017-03-24T14:59:00","updated_at":"2025-08-26T12:00:37.549950+00:00","description":"\nApache POI in versions prior to release 3.15 allows remote attackers to\ncause a denial of service (CPU consumption) via a specially crafted OOXML\nfile, aka an XML Entity Expansion (XEE) attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/03/20/9","https://www.cve.org/CVERecord?id=CVE-2017-5644"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858301"],"patches":{"libapache-poi-java":[]},"tags":{},"packages":[{"name":"libapache-poi-java","source":"https://ubuntu.com/security/cve?package=libapache-poi-java","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libapache-poi-java","debian":"https://tracker.debian.org/pkg/libapache-poi-java","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.17-1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needs-triage","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"4.0.1-1~18.03","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8556","published":"2017-03-24T14:59:00","updated_at":"2025-08-25T21:48:10.458576+00:00","description":"\nLocal privilege escalation vulnerability in the Gentoo QEMU package before\n2.5.0-r1.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"gentoo-specific issue, not suid in Debian/Ubuntu"}],"codename":null,"priority":"medium","cvss3":10.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":10.0,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2015/12/14/5","https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=183dd7394703b49c7af441a","https://www.cve.org/CVERecord?id=CVE-2015-8556"],"bugs":[""],"patches":{"qemu-kvm":[],"qemu":[]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"not-affected","description":"","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"vivid","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"wily","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7261","published":"2017-03-24T00:00:00","updated_at":"2026-07-04T07:44:49.982497+00:00","description":"\nThe vmw_surface_define_ioctl function in\ndrivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.5\ndoes not check for a zero value of certain levels data, which allows local\nusers to cause a denial of service (ZERO_SIZE_PTR dereference, and GPF and\npossibly panic) via a crafted ioctl call for a /dev/dri/renderD* device.","ubuntu_description":"\nIt was discovered that a NULL pointer dereference existed in the Direct\nRendering Manager (DRM) driver for VMWare devices in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).","notes":[{"author":"jdstrand","note":"android kernels (flo, goldfish, grouper, maguro, mako and manta) are\nnot supported on the Ubuntu Touch 14.10 and earlier preview kernels\nlinux-lts-saucy no longer receives official support\nlinux-lts-quantal no longer receives official support"}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://marc.info/?t=149037004200005&r=1&w=2","https://bugzilla.redhat.com/show_bug.cgi?id=1435719","https://lists.freedesktop.org/archives/dri-devel/2017-March/136814.html","https://ubuntu.com/security/notices/USN-3293-1","https://ubuntu.com/security/notices/USN-3291-1","https://ubuntu.com/security/notices/USN-3291-2","https://ubuntu.com/security/notices/USN-3291-3","https://ubuntu.com/security/notices/USN-3361-1","https://ubuntu.com/security/notices/USN-3406-1","https://ubuntu.com/security/notices/USN-3406-2","https://www.cve.org/CVERecord?id=CVE-2017-7261"],"bugs":[""],"patches":{"linux":["break-fix: - 36274ab8c596f1240c606bb514da329add2a1bcd"],"linux-ti-omap4":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-hwe-5.4":[],"linux-hwe-5.15":[],"linux-hwe-6.8":[],"linux-aws-5.4":[],"linux-aws-5.15":[],"linux-aws-hwe":[],"linux-azure-4.15":[],"linux-azure-5.4":[],"linux-azure-5.15":[],"linux-azure-fde":[],"linux-azure-fde-5.15":[],"linux-bluefield":[],"linux-fips":[],"linux-aws-fips":[],"linux-azure-fips":[],"linux-gcp-fips":[],"linux-gcp-4.15":[],"linux-gcp-5.4":[],"linux-gcp-5.15":[],"linux-gkeop":[],"linux-gkeop-5.15":[],"linux-ibm":[],"linux-ibm-5.4":[],"linux-ibm-5.15":[],"linux-intel":[],"linux-intel-iotg":[],"linux-intel-iotg-5.15":[],"linux-iot":[],"linux-intel-iot-realtime":[],"linux-lowlatency":[],"linux-lowlatency-hwe-5.15":[],"linux-lowlatency-hwe-6.8":[],"linux-nvidia":[],"linux-nvidia-6.5":[],"linux-nvidia-6.8":[],"linux-nvidia-lowlatency":[],"linux-oracle":[],"linux-oracle-5.4":[],"linux-oracle-5.15":[],"linux-oem-6.8":[],"linux-raspi":[],"linux-raspi-5.4":[],"linux-raspi-realtime":[],"linux-realtime":[],"linux-riscv":[],"linux-riscv-5.15":[],"linux-riscv-6.8":[],"linux-xilinx-zynqmp":[],"linux-aws-6.8":[],"linux-gcp-6.8":[],"linux-oracle-6.8":[],"linux-azure-6.8":[],"linux-oem-6.11":[],"linux-hwe-6.11":[],"linux-hwe-6.14":[],"linux-aws-6.14":[],"linux-azure-6.11":[],"linux-azure-nvidia":[],"linux-gcp-6.11":[],"linux-gcp-6.14":[],"linux-ibm-6.8":[],"linux-lowlatency-hwe-6.11":[],"linux-nvidia-tegra":[],"linux-nvidia-tegra-5.15":[],"linux-nvidia-tegra-igx":[],"linux-oracle-6.14":[],"linux-oem-6.14":[],"linux-riscv-6.14":[],"linux-nvidia-6.11":[],"linux-realtime-6.8":[],"linux-realtime-6.14":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux-aws-fips","source":"https://ubuntu.com/security/cve?package=linux-aws-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-fips","debian":"https://tracker.debian.org/pkg/linux-aws-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-2000.4","component":null,"pocket":"fips"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1052.57+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips2","component":null,"pocket":"fips"}]},{"name":"linux-azure-fips","source":"https://ubuntu.com/security/cve?package=linux-azure-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fips","debian":"https://tracker.debian.org/pkg/linux-azure-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1058.66+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1022.22+fips1","component":null,"pocket":"fips"}]},{"name":"linux-gcp-fips","source":"https://ubuntu.com/security/cve?package=linux-gcp-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-fips","debian":"https://tracker.debian.org/pkg/linux-gcp-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1048.56+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips1","component":null,"pocket":"fips"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.10.0-21.23","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-129.178","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-78.99","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"4.10.0-21.23","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-16.19","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-9.12","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-19.19","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1017.26","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1008.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1008.8","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-aws-5.15","source":"https://ubuntu.com/security/cve?package=linux-aws-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.15","debian":"https://tracker.debian.org/pkg/linux-aws-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.19~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-5.4","source":"https://ubuntu.com/security/cve?package=linux-aws-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.4","debian":"https://tracker.debian.org/pkg/linux-aws-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1020.20~18.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-6.14","source":"https://ubuntu.com/security/cve?package=linux-aws-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.14","debian":"https://tracker.debian.org/pkg/linux-aws-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-aws-6.8","source":"https://ubuntu.com/security/cve?package=linux-aws-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.8","debian":"https://tracker.debian.org/pkg/linux-aws-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1009.9~22.04.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1031.33~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"superseded by linux-azure-5.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1006.6","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1006.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.11.0-1015.15","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1082.92","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.8~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1022.22~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-6.11","source":"https://ubuntu.com/security/cve?package=linux-azure-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.11","debian":"https://tracker.debian.org/pkg/linux-azure-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-azure-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-azure-6.8","source":"https://ubuntu.com/security/cve?package=linux-azure-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.8","debian":"https://tracker.debian.org/pkg/linux-azure-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-azure-fde","source":"https://ubuntu.com/security/cve?package=linux-azure-fde","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde","debian":"https://tracker.debian.org/pkg/linux-azure-fde","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1019.24.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.14.0-1012.12","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1041.48","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-azure-fde-5.15]","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-fde-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]},{"name":"linux-azure-nvidia","source":"https://ubuntu.com/security/cve?package=linux-azure-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-azure-nvidia","debian":"https://tracker.debian.org/pkg/linux-azure-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1013.14","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-bluefield","source":"https://ubuntu.com/security/cve?package=linux-bluefield","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-bluefield","debian":"https://tracker.debian.org/pkg/linux-bluefield","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1011.14","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-fips","source":"https://ubuntu.com/security/cve?package=linux-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-fips","debian":"https://tracker.debian.org/pkg/linux-fips","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-92.102+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1017.22~recert1","component":null,"pocket":"fips"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1011.12","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.8","component":null,"pocket":"fips"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.10.0-1004.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"superseded by linux-gcp-5.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1003.3","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1071.81","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.15","debian":"https://tracker.debian.org/pkg/linux-gcp-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1006.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.4","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.4","debian":"https://tracker.debian.org/pkg/linux-gcp-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.11","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.11","debian":"https://tracker.debian.org/pkg/linux-gcp-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-gcp-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.14","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.14","debian":"https://tracker.debian.org/pkg/linux-gcp-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.8","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.8","debian":"https://tracker.debian.org/pkg/linux-gcp-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1010.11~22.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1013.13","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop","source":"https://ubuntu.com/security/cve?package=linux-gkeop","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop","debian":"https://tracker.debian.org/pkg/linux-gkeop","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1008.9","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop-5.15","source":"https://ubuntu.com/security/cve?package=linux-gkeop-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-gkeop-5.15","debian":"https://tracker.debian.org/pkg/linux-gkeop-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.10.0-32.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"replaced by linux-hwe-5.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-37.41~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.14","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.14","debian":"https://tracker.debian.org/pkg/linux-hwe-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-24.24~24.04.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.10.0-27.30~16.04.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"superseded by linux-hwe-5.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm","source":"https://ubuntu.com/security/cve?package=linux-ibm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm","debian":"https://tracker.debian.org/pkg/linux-ibm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1009.9","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.5","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.15","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.15","debian":"https://tracker.debian.org/pkg/linux-ibm-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1034.37~20.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.4","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.4","debian":"https://tracker.debian.org/pkg/linux-ibm-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1010.11~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm-6.8","source":"https://ubuntu.com/security/cve?package=linux-ibm-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ibm-6.8","debian":"https://tracker.debian.org/pkg/linux-ibm-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-intel","source":"https://ubuntu.com/security/cve?package=linux-intel","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel","debian":"https://tracker.debian.org/pkg/linux-intel","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iot-realtime","source":"https://ubuntu.com/security/cve?package=linux-intel-iot-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iot-realtime","debian":"https://tracker.debian.org/pkg/linux-intel-iot-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1021.26","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg","debian":"https://tracker.debian.org/pkg/linux-intel-iotg","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1004.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg-5.15","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg-5.15","debian":"https://tracker.debian.org/pkg/linux-intel-iotg-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-iot","source":"https://ubuntu.com/security/cve?package=linux-iot","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-iot","debian":"https://tracker.debian.org/pkg/linux-iot","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1001.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1007.12","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency","debian":"https://tracker.debian.org/pkg/linux-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-22.22","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"replaced by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was ignored [end of life, was needed]","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.4.0-78.99~14.04.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"xenial","status":"ignored","description":"end of standard support","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-nvidia","source":"https://ubuntu.com/security/cve?package=linux-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia","debian":"https://tracker.debian.org/pkg/linux-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1005.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.11","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.11","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1002.2","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.5","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.5","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.5","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.5.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.8","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.8","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-nvidia-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-lowlatency","debian":"https://tracker.debian.org/pkg/linux-nvidia-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1009.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1013.13","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-5.15","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-5.15","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1009.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-igx","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-igx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-igx","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-igx","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"replaced by linux-hwe-5.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.11","source":"https://ubuntu.com/security/cve?package=linux-oem-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.11","debian":"https://tracker.debian.org/pkg/linux-oem-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1007.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.14","source":"https://ubuntu.com/security/cve?package=linux-oem-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.14","debian":"https://tracker.debian.org/pkg/linux-oem-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1005.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-oem-6.8","source":"https://ubuntu.com/security/cve?package=linux-oem-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.8","debian":"https://tracker.debian.org/pkg/linux-oem-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1010.10","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1008.10","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1008.10~16.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1005.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1006.6","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.15","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.15","debian":"https://tracker.debian.org/pkg/linux-oracle-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.4","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.4","debian":"https://tracker.debian.org/pkg/linux-oracle-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.14","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.14","debian":"https://tracker.debian.org/pkg/linux-oracle-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.8","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.8","debian":"https://tracker.debian.org/pkg/linux-oracle-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1006.6~22.04.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1005.7","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-1004.4","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1013.13~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi-realtime","source":"https://ubuntu.com/security/cve?package=linux-raspi-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi-realtime","debian":"https://tracker.debian.org/pkg/linux-raspi-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.7.0-2001.1","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.10.0-1005.7","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1055.62","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"4.10.0-1005.7","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [replaced by linux-raspi]","component":null,"pocket":"security"}]},{"name":"linux-realtime","source":"https://ubuntu.com/security/cve?package=linux-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime","debian":"https://tracker.debian.org/pkg/linux-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1006.6","component":null,"pocket":"realtime"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.1-1015.16","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.14","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.14","debian":"https://tracker.debian.org/pkg/linux-realtime-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1003.3~24.04.3","component":null,"pocket":"realtime"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.8","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.8","debian":"https://tracker.debian.org/pkg/linux-realtime-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.1-1004.4~22.04.1","component":null,"pocket":"realtime"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"6.8.0-31.31.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was ignored [superseded by linux-riscv-5.8]","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.15","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.15","debian":"https://tracker.debian.org/pkg/linux-riscv-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.17~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.14","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.14","debian":"https://tracker.debian.org/pkg/linux-riscv-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-22.22.1~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.8","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.8","debian":"https://tracker.debian.org/pkg/linux-riscv-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.4.0-1058.62","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.4.0-1058.62","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"4.4.0-1058.62","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"4.4.0-1058.62","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.4.0-1077.82","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-xilinx-zynqmp","source":"https://ubuntu.com/security/cve?package=linux-xilinx-zynqmp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=linux-xilinx-zynqmp","debian":"https://tracker.debian.org/pkg/linux-xilinx-zynqmp","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1020.24","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1022.26","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.11~rc6, 4.4.61","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3291-3","USN-3291-1","USN-3406-1","USN-3406-2","USN-3361-1","USN-3293-1","USN-3291-2"],"notices":[{"id":"USN-3291-3","title":"Linux kernel (Xenial HWE) vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-05-17T18:25:56.787051","description":"USN-3291-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu\n14.04 LTS.\n\nDmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linux\nkernel contained a stack-based buffer overflow. A local attacker with\naccess to an sg device could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-7187)\n\nIt was discovered that a NULL pointer dereference existed in the Direct\nRendering Manager (DRM) driver for VMWare devices in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2017-7261)\n\nLi Qiang discovered that an integer overflow vulnerability existed in the\nDirect Rendering Manager (DRM) driver for VMWare devices in the Linux\nkernel. A local attacker could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2017-7294)\n\nIt was discovered that an information leak existed in the set_mempolicy and\nmbind compat syscalls in the Linux kernel. A local attacker could use this\nto expose sensitive information (kernel memory). (CVE-2017-7616)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux-lts-xenial","version":"4.4.0-78.99~14.04.2","description":"Linux hardware enablement kernel from Xenial for Trusty","is_source":true},{"name":"linux-image-4.4.0-78-generic","version":"4.4.0-78.99~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-78.99~14.04.2","pocket":"security"},{"name":"linux-image-4.4.0-78-generic-lpae","version":"4.4.0-78.99~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-78.99~14.04.2","pocket":"security"},{"name":"linux-image-4.4.0-78-lowlatency","version":"4.4.0-78.99~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-78.99~14.04.2","pocket":"security"},{"name":"linux-image-4.4.0-78-powerpc-e500mc","version":"4.4.0-78.99~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-78.99~14.04.2","pocket":"security"},{"name":"linux-image-4.4.0-78-powerpc-smp","version":"4.4.0-78.99~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-78.99~14.04.2","pocket":"security"},{"name":"linux-image-4.4.0-78-powerpc64-emb","version":"4.4.0-78.99~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-78.99~14.04.2","pocket":"security"},{"name":"linux-image-4.4.0-78-powerpc64-smp","version":"4.4.0-78.99~14.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-78.99~14.04.2","pocket":"security"},{"name":"linux-image-extra-4.4.0-78-generic","version":"4.4.0-78.99~14.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-xenial/4.4.0-78.99~14.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-7187","CVE-2017-7261","CVE-2017-7294","CVE-2017-7616"]},{"id":"USN-3291-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-05-17T00:22:17.751142","description":"Dmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linux\nkernel contained a stack-based buffer overflow. A local attacker with\naccess to an sg device could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-7187)\n\nIt was discovered that a NULL pointer dereference existed in the Direct\nRendering Manager (DRM) driver for VMWare devices in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2017-7261)\n\nLi Qiang discovered that an integer overflow vulnerability existed in the\nDirect Rendering Manager (DRM) driver for VMWare devices in the Linux\nkernel. A local attacker could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2017-7294)\n\nIt was discovered that an information leak existed in the set_mempolicy and\nmbind compat syscalls in the Linux kernel. A local attacker could use this\nto expose sensitive information (kernel memory). (CVE-2017-7616)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux","version":"4.4.0-78.99","description":"Linux kernel","is_source":true},{"name":"linux-image-4.4.0-78-generic","version":"4.4.0-78.99","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-78.99","pocket":"security"},{"name":"linux-image-4.4.0-78-generic-lpae","version":"4.4.0-78.99","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-78.99","pocket":"security"},{"name":"linux-image-4.4.0-78-lowlatency","version":"4.4.0-78.99","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-78.99","pocket":"security"},{"name":"linux-image-4.4.0-78-powerpc-e500mc","version":"4.4.0-78.99","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-78.99","pocket":"security"},{"name":"linux-image-4.4.0-78-powerpc-smp","version":"4.4.0-78.99","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-78.99","pocket":"security"},{"name":"linux-image-4.4.0-78-powerpc64-emb","version":"4.4.0-78.99","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-78.99","pocket":"security"},{"name":"linux-image-4.4.0-78-powerpc64-smp","version":"4.4.0-78.99","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-78.99","pocket":"security"},{"name":"linux-image-extra-4.4.0-78-generic","version":"4.4.0-78.99","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.4.0-78.99","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-7187","CVE-2017-7261","CVE-2017-7294","CVE-2017-7616"]},{"id":"USN-3406-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-08-28T21:24:38.931701","description":"It was discovered that an out of bounds read vulnerability existed in the\nassociative array implementation in the Linux kernel. A local attacker\ncould use this to cause a denial of service (system crash) or expose\nsensitive information. (CVE-2016-7914)\n\nIt was discovered that a NULL pointer dereference existed in the Direct\nRendering Manager (DRM) driver for VMWare devices in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2017-7261)\n\nIt was discovered that the USB Cypress HID drivers for the Linux kernel did\nnot properly validate reported information from the device. An attacker\nwith physical access could use this to expose sensitive information (kernel\nmemory). (CVE-2017-7273)\n\nA reference count bug was discovered in the Linux kernel ipx protocol\nstack. A local attacker could exploit this flaw to cause a denial of\nservice or possibly other unspecified problems. (CVE-2017-7487)\n\nHuang Weller discovered that the ext4 filesystem implementation in the\nLinux kernel mishandled a needs-flushing-before-commit list. A local\nattacker could use this to expose sensitive information. (CVE-2017-7495)\n\nIt was discovered that an information leak existed in the set_mempolicy and\nmbind compat syscalls in the Linux kernel. A local attacker could use this\nto expose sensitive information (kernel memory). (CVE-2017-7616)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-129.178","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-129-generic","version":"3.13.0-129.178","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-129.178","pocket":"security"},{"name":"linux-image-3.13.0-129-generic-lpae","version":"3.13.0-129.178","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-129.178","pocket":"security"},{"name":"linux-image-3.13.0-129-lowlatency","version":"3.13.0-129.178","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-129.178","pocket":"security"},{"name":"linux-image-3.13.0-129-powerpc-e500","version":"3.13.0-129.178","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-129.178","pocket":"security"},{"name":"linux-image-3.13.0-129-powerpc-e500mc","version":"3.13.0-129.178","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-129.178","pocket":"security"},{"name":"linux-image-3.13.0-129-powerpc-smp","version":"3.13.0-129.178","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-129.178","pocket":"security"},{"name":"linux-image-3.13.0-129-powerpc64-emb","version":"3.13.0-129.178","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-129.178","pocket":"security"},{"name":"linux-image-3.13.0-129-powerpc64-smp","version":"3.13.0-129.178","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-129.178","pocket":"security"},{"name":"linux-image-extra-3.13.0-129-generic","version":"3.13.0-129.178","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-129.178","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-7914","CVE-2017-7261","CVE-2017-7273","CVE-2017-7487","CVE-2017-7495","CVE-2017-7616"]},{"id":"USN-3406-2","title":"Linux kernel (Trusty HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-08-29T18:03:33.189430","description":"USN-3406-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu\n12.04 ESM.\n\nIt was discovered that an out of bounds read vulnerability existed in the\nassociative array implementation in the Linux kernel. A local attacker\ncould use this to cause a denial of service (system crash) or expose\nsensitive information. (CVE-2016-7914)\n\nIt was discovered that a NULL pointer dereference existed in the Direct\nRendering Manager (DRM) driver for VMWare devices in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2017-7261)\n\nIt was discovered that the USB Cypress HID drivers for the Linux kernel did\nnot properly validate reported information from the device. An attacker\nwith physical access could use this to expose sensitive information (kernel\nmemory). (CVE-2017-7273)\n\nA reference count bug was discovered in the Linux kernel ipx protocol\nstack. A local attacker could exploit this flaw to cause a denial of\nservice or possibly other unspecified problems. (CVE-2017-7487)\n\nHuang Weller discovered that the ext4 filesystem implementation in the\nLinux kernel mishandled a needs-flushing-before-commit list. A local\nattacker could use this to expose sensitive information. (CVE-2017-7495)\n\nIt was discovered that an information leak existed in the set_mempolicy and\nmbind compat syscalls in the Linux kernel. A local attacker could use this\nto expose sensitive information (kernel memory). (CVE-2017-7616)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-trusty","version":"3.13.0-129.178~precise1","description":"Linux hardware enablement kernel from Trusty for Precise ESM","is_source":true},{"name":"linux-image-3.13.0-129-generic","version":"3.13.0-129.178~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-129.178~precise1"},{"name":"linux-image-generic-lpae-lts-trusty","version":"3.13.0.129.119","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-129.178~precise1"},{"name":"linux-image-generic-lts-trusty","version":"3.13.0.129.119","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-129.178~precise1"},{"name":"linux-image-3.13.0-129-generic-lpae","version":"3.13.0-129.178~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-129.178~precise1"}]},"type":"USN","cves_ids":["CVE-2016-7914","CVE-2017-7261","CVE-2017-7273","CVE-2017-7487","CVE-2017-7495","CVE-2017-7616"]},{"id":"USN-3361-1","title":"Linux kernel (HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-07-21T09:59:15.537079","description":"USN-3358-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04.\nThis update provides the corresponding updates for the Linux Hardware\nEnablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS. Please\nnote that this update changes the Linux HWE kernel to the 4.10 based\nkernel from Ubuntu 17.04, superseding the 4.8 based HWE kernel from\nUbuntu 16.10.\n\nBen Harris discovered that the Linux kernel would strip extended privilege\nattributes of files when performing a failed unprivileged system call. A\nlocal attacker could use this to cause a denial of service. (CVE-2015-1350)\n\nRalf Spenneberg discovered that the ext4 implementation in the Linux kernel\ndid not properly validate meta block groups. An attacker with physical\naccess could use this to specially craft an ext4 image that causes a denial\nof service (system crash). (CVE-2016-10208)\n\nPeter Pi discovered that the colormap handling for frame buffer devices in\nthe Linux kernel contained an integer overflow. A local attacker could use\nthis to disclose sensitive information (kernel memory). (CVE-2016-8405)\n\nIt was discovered that an integer overflow existed in the InfiniBand RDMA\nover ethernet (RXE) transport implementation in the Linux kernel. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2016-8636)\n\nVlad Tsyrklevich discovered an integer overflow vulnerability in the VFIO\nPCI driver for the Linux kernel. A local attacker with access to a vfio PCI\ndevice file could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2016-9083, CVE-2016-9084)\n\nCAI Qian discovered that the sysctl implementation in the Linux kernel did\nnot properly perform reference counting in some situations. An unprivileged\nattacker could use this to cause a denial of service (system hang).\n(CVE-2016-9191)\n\nIt was discovered that the keyring implementation in the Linux kernel in\nsome situations did not prevent special internal keyrings from being joined\nby userspace keyrings. A privileged local attacker could use this to bypass\nmodule verification. (CVE-2016-9604)\n\nDmitry Vyukov, Andrey Konovalov, Florian Westphal, and Eric Dumazet\ndiscovered that the netfiler subsystem in the Linux kernel mishandled IPv6\npacket reassembly. A local user could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2016-9755)\n\nAndy Lutomirski and Willy Tarreau discovered that the KVM implementation in\nthe Linux kernel did not properly emulate instructions on the SS segment\nregister. A local attacker in a guest virtual machine could use this to\ncause a denial of service (guest OS crash) or possibly gain administrative\nprivileges in the guest OS. (CVE-2017-2583)\n\nDmitry Vyukov discovered that the KVM implementation in the Linux kernel\nimproperly emulated certain instructions. A local attacker could use this\nto obtain sensitive information (kernel memory). (CVE-2017-2584)\n\nDmitry Vyukov discovered that KVM implementation in the Linux kernel\nimproperly emulated the VMXON instruction. A local attacker in a guest OS\ncould use this to cause a denial of service (memory consumption) in the\nhost OS. (CVE-2017-2596)\n\nIt was discovered that SELinux in the Linux kernel did not properly handle\nempty writes to /proc/pid/attr. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2017-2618)\n\nDaniel Jiang discovered that a race condition existed in the ipv4 ping\nsocket implementation in the Linux kernel. A local privileged attacker\ncould use this to cause a denial of service (system crash). (CVE-2017-2671)\n\nIt was discovered that the freelist-randomization in the SLAB memory\nallocator allowed duplicate freelist entries. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-5546)\n\nIt was discovered that the KLSI KL5KUSB105 serial-to-USB device driver in\nthe Linux kernel did not properly initialize memory related to logging. A\nlocal attacker could use this to expose sensitive information (kernel\nmemory). (CVE-2017-5549)\n\nIt was discovered that a fencepost error existed in the pipe_advance()\nfunction in the Linux kernel. A local attacker could use this to expose\nsensitive information (kernel memory). (CVE-2017-5550)\n\nIt was discovered that the Linux kernel did not clear the setgid bit during\na setxattr call on a tmpfs filesystem. A local attacker could use this to\ngain elevated group privileges. (CVE-2017-5551)\n\nMurray McAllister discovered that an integer overflow existed in the\nVideoCore DRM driver of the Linux kernel. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2017-5576)\n\nGareth Evans discovered that the shm IPC subsystem in the Linux kernel did\nnot properly restrict mapping page zero. A local privileged attacker could\nuse this to execute arbitrary code. (CVE-2017-5669)\n\nAndrey Konovalov discovered an out-of-bounds access in the IPv6 Generic\nRouting Encapsulation (GRE) tunneling implementation in the Linux kernel.\nAn attacker could use this to possibly expose sensitive information.\n(CVE-2017-5897)\n\nAndrey Konovalov discovered that the IPv4 implementation in the Linux\nkernel did not properly handle invalid IP options in some situations. An\nattacker could use this to cause a denial of service or possibly execute\narbitrary code. (CVE-2017-5970)\n\nDi Shen discovered that a race condition existed in the perf subsystem of\nthe Linux kernel. A local attacker could use this to cause a denial of\nservice or possibly gain administrative privileges. (CVE-2017-6001)\n\nDmitry Vyukov discovered that the Linux kernel did not properly handle TCP\npackets with the URG flag. A remote attacker could use this to cause a\ndenial of service. (CVE-2017-6214)\n\nAndrey Konovalov discovered that the LLC subsytem in the Linux kernel did\nnot properly set up a destructor in certain situations. A local attacker\ncould use this to cause a denial of service (system crash). (CVE-2017-6345)\n\nIt was discovered that a race condition existed in the AF_PACKET handling\ncode in the Linux kernel. A local attacker could use this to cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2017-6346)\n\nAndrey Konovalov discovered that the IP layer in the Linux kernel made\nimproper assumptions about internal data layout when performing checksums.\nA local attacker could use this to cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2017-6347)\n\nDmitry Vyukov discovered race conditions in the Infrared (IrDA) subsystem\nin the Linux kernel. A local attacker could use this to cause a denial of\nservice (deadlock). (CVE-2017-6348)\n\nDmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linux\nkernel contained a stack-based buffer overflow. A local attacker with\naccess to an sg device could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-7187)\n\nIt was discovered that a NULL pointer dereference existed in the Direct\nRendering Manager (DRM) driver for VMWare devices in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2017-7261)\n\nIt was discovered that the USB Cypress HID drivers for the Linux kernel did\nnot properly validate reported information from the device. An attacker\nwith physical access could use this to expose sensitive information (kernel\nmemory). (CVE-2017-7273)\n\nEric Biggers discovered a memory leak in the keyring implementation in the\nLinux kernel. A local attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-7472)\n\nIt was discovered that an information leak existed in the set_mempolicy and\nmbind compat syscalls in the Linux kernel. A local attacker could use this\nto expose sensitive information (kernel memory). (CVE-2017-7616)\n\nSabrina Dubroca discovered that the asynchronous cryptographic hash (ahash)\nimplementation in the Linux kernel did not properly handle a full request\nqueue. A local attacker could use this to cause a denial of service\n(infinite recursion). (CVE-2017-7618)\n\nTuomas Haanpää and Ari Kauppi discovered that the NFSv2 and NFSv3 server\nimplementations in the Linux kernel did not properly handle certain long\nRPC replies. A remote attacker could use this to cause a denial of service\n(system crash). (CVE-2017-7645)\n\nTommi Rantala and Brad Spengler discovered that the memory manager in the\nLinux kernel did not properly enforce the CONFIG_STRICT_DEVMEM protection\nmechanism. A local attacker with access to /dev/mem could use this to\nexpose sensitive information or possibly execute arbitrary code.\n(CVE-2017-7889)\n\nTuomas Haanpää and Ari Kauppi discovered that the NFSv2 and NFSv3 server\nimplementations in the Linux kernel did not properly check for the end of\nbuffer. A remote attacker could use this to craft requests that cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2017-7895)\n\nIt was discovered that an integer underflow existed in the Edgeport USB\nSerial Converter device driver of the Linux kernel. An attacker with\nphysical access could use this to expose sensitive information (kernel\nmemory). (CVE-2017-8924)\n\nIt was discovered that the USB ZyXEL omni.net LCD PLUS driver in the Linux\nkernel did not properly perform reference counting. A local attacker could\nuse this to cause a denial of service (tty exhaustion). (CVE-2017-8925)\n\nJann Horn discovered that bpf in Linux kernel does not restrict the output\nof the print_bpf_insn function. A local attacker could use this to obtain\nsensitive address information. (CVE-2017-9150)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux-hwe","version":"4.10.0-27.30~16.04.2","description":"Linux hardware enablement (HWE) kernel","is_source":true},{"name":"linux-image-4.10.0-27-generic","version":"4.10.0-27.30~16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.10.0-27.30~16.04.2","pocket":"security"},{"name":"linux-image-4.10.0-27-generic-lpae","version":"4.10.0-27.30~16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.10.0-27.30~16.04.2","pocket":"security"},{"name":"linux-image-4.10.0-27-lowlatency","version":"4.10.0-27.30~16.04.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.10.0-27.30~16.04.2","pocket":"security"},{"name":"linux-image-extra-4.10.0-27-generic","version":"4.10.0-27.30~16.04.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-hwe","version_link":"https://launchpad.net/ubuntu/+source/linux-hwe/4.10.0-27.30~16.04.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2015-1350","CVE-2016-10208","CVE-2016-8405","CVE-2016-8636","CVE-2016-9083","CVE-2016-9084","CVE-2016-9191","CVE-2016-9604","CVE-2016-9755","CVE-2017-2583","CVE-2017-2584","CVE-2017-2596","CVE-2017-2618","CVE-2017-2671","CVE-2017-5546","CVE-2017-5549","CVE-2017-5550","CVE-2017-5551","CVE-2017-5576","CVE-2017-5669","CVE-2017-5897","CVE-2017-5970","CVE-2017-6001","CVE-2017-6214","CVE-2017-6345","CVE-2017-6346","CVE-2017-6347","CVE-2017-6348","CVE-2017-7187","CVE-2017-7261","CVE-2017-7273","CVE-2017-7472","CVE-2017-7616","CVE-2017-7618","CVE-2017-7645","CVE-2017-7889","CVE-2017-7895","CVE-2017-8924","CVE-2017-8925","CVE-2017-9150"]},{"id":"USN-3293-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-05-17T01:25:05.987321","description":"Dmitry Vyukov discovered that KVM implementation in the Linux kernel\nimproperly emulated the VMXON instruction. A local attacker in a guest OS\ncould use this to cause a denial of service (memory consumption) in the\nhost OS. (CVE-2017-2596)\n\nDmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linux\nkernel contained a stack-based buffer overflow. A local attacker with\naccess to an sg device could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-7187)\n\nIt was discovered that a NULL pointer dereference existed in the Direct\nRendering Manager (DRM) driver for VMWare devices in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2017-7261)\n\nLi Qiang discovered that an integer overflow vulnerability existed in the\nDirect Rendering Manager (DRM) driver for VMWare devices in the Linux\nkernel. A local attacker could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2017-7294)\n\nJason Donenfeld discovered a heap overflow in the MACsec module in the\nLinux kernel. An attacker could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2017-7477)\n\nIt was discovered that an information leak existed in the set_mempolicy and\nmbind compat syscalls in the Linux kernel. A local attacker could use this\nto expose sensitive information (kernel memory). (CVE-2017-7616)\n","is_hidden":false,"release_packages":{"zesty":[{"name":"linux-raspi2","version":"4.10.0-1005.7","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux","version":"4.10.0-21.23","description":"Linux kernel","is_source":true},{"name":"linux-image-4.10.0-21-generic-lpae","version":"4.10.0-21.23","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.10.0-21.23"},{"name":"linux-image-generic","version":"4.10.0.21.23","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.10.0-1005-raspi2","version":"4.10.0-1005.7","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.10.0-1005.7"},{"name":"linux-image-generic-lpae","version":"4.10.0.21.23","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-4.10.0-21-generic","version":"4.10.0-21.23","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.10.0-21.23"},{"name":"linux-image-4.10.0-21-lowlatency","version":"4.10.0-21.23","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/4.10.0-21.23"},{"name":"linux-image-lowlatency","version":"4.10.0.21.23","is_source":false,"source_link":null,"version_link":null},{"name":"linux-image-raspi2","version":"4.10.0.1005.7","is_source":false,"source_link":null,"version_link":null}]},"type":"USN","cves_ids":["CVE-2017-2596","CVE-2017-7187","CVE-2017-7261","CVE-2017-7294","CVE-2017-7477","CVE-2017-7616"]},{"id":"USN-3291-2","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-05-17T18:23:37.195003","description":"USN-3291-1 fixed vulnerabilities in the generic Linux kernel.\nThis update provides the corresponding updates for the Linux kernel\nbuilt for specific processors and cloud environments.\n\nDmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linux\nkernel contained a stack-based buffer overflow. A local attacker with\naccess to an sg device could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-7187)\n\nIt was discovered that a NULL pointer dereference existed in the Direct\nRendering Manager (DRM) driver for VMWare devices in the Linux kernel. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2017-7261)\n\nLi Qiang discovered that an integer overflow vulnerability existed in the\nDirect Rendering Manager (DRM) driver for VMWare devices in the Linux\nkernel. A local attacker could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2017-7294)\n\nIt was discovered that an information leak existed in the set_mempolicy and\nmbind compat syscalls in the Linux kernel. A local attacker could use this\nto expose sensitive information (kernel memory). (CVE-2017-7616)\n","is_hidden":false,"release_packages":{"xenial":[{"name":"linux-aws","version":"4.4.0-1017.26","description":"Linux kernel for Amazon Web Services (AWS) systems","is_source":true},{"name":"linux-gke","version":"4.4.0-1013.13","description":"Linux kernel for Google Container Engine (GKE) systems","is_source":true},{"name":"linux-raspi2","version":"4.4.0-1055.62","description":"Linux kernel for Raspberry Pi 2","is_source":true},{"name":"linux-snapdragon","version":"4.4.0-1058.62","description":"Linux kernel for Snapdragon Processors","is_source":true},{"name":"linux-image-4.4.0-1013-gke","version":"4.4.0-1013.13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-gke","version_link":"https://launchpad.net/ubuntu/+source/linux-gke/4.4.0-1013.13","pocket":"security"},{"name":"linux-image-4.4.0-1017-aws","version":"4.4.0-1017.26","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-aws","version_link":"https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1017.26","pocket":"security"},{"name":"linux-image-4.4.0-1055-raspi2","version":"4.4.0-1055.62","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-raspi2","version_link":"https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1055.62","pocket":"security"},{"name":"linux-image-4.4.0-1058-snapdragon","version":"4.4.0-1058.62","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon","version_link":"https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1058.62","pocket":"security"},{"name":"linux-image-extra-4.4.0-1013-gke","version":"4.4.0-1013.13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-gke","version_link":"https://launchpad.net/ubuntu/+source/linux-gke/4.4.0-1013.13","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2017-7187","CVE-2017-7261","CVE-2017-7294","CVE-2017-7616"]}]},{"id":"CVE-2017-6507","published":"2017-03-24T00:00:00","updated_at":"2025-08-25T22:36:26.245761+00:00","description":"\nAn issue was discovered in AppArmor before 2.12. Incorrect handling of\nunknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or\nsystemd unit files allows an attacker to possibly have increased attack\nsurfaces of processes that were intended to be confined by AppArmor. This\nis due to the common logic to handle 'restart' operations removing AppArmor\nprofiles that aren't found in the typical filesystem locations, such as\n/etc/apparmor.d/. Userspace projects that manage their own AppArmor\nprofiles in atypical directories, such as what's done by LXD and Docker,\nare affected by this flaw in the AppArmor init script logic.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3247-1","https://www.cve.org/CVERecord?id=CVE-2017-6507"],"bugs":["https://launchpad.net/bugs/1668892"],"patches":{"apparmor":["upstream: http://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3647","upstream: http://bazaar.launchpad.net/~apparmor-dev/apparmor/master/revision/3648"]},"tags":{},"packages":[{"name":"apparmor","source":"https://ubuntu.com/security/cve?package=apparmor","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=apparmor","debian":"https://tracker.debian.org/pkg/apparmor","statuses":[{"release_codename":"precise","status":"released","description":"2.7.102-0ubuntu3.11","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.10.95-0ubuntu2.6~14.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.10.95-0ubuntu2.6","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"2.10.95-4ubuntu5.3","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"2.11.0-2ubuntu3","component":null,"pocket":"security"}]}],"notices_ids":["USN-3247-1"],"notices":[{"id":"USN-3247-1","title":"AppArmor vulnerability","summary":"AppArmor could remove the confinement from some programs.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nA new utility, called aa-remove-unknown, was added to assist with profiles that\nwould have been previously unloaded when AppArmor was restarted or upgraded.\n","references":[],"published":"2017-03-28T19:11:09.616352","description":"Stéphane Graber discovered that AppArmor incorrectly unloaded some profiles\nwhen restarted or upgraded, contrary to expected behavior.\n","is_hidden":false,"release_packages":{"precise":[{"name":"apparmor","version":"2.7.102-0ubuntu3.11","description":"Linux security system","is_source":true},{"name":"apparmor","version":"2.7.102-0ubuntu3.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.7.102-0ubuntu3.11"}],"trusty":[{"name":"apparmor","version":"2.10.95-0ubuntu2.6~14.04.1","description":"Linux security system","is_source":true},{"name":"apparmor","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"apparmor-docs","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"apparmor-easyprof","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"apparmor-notify","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"apparmor-profiles","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"apparmor-utils","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"dh-apparmor","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"libapache2-mod-apparmor","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"libapparmor-dev","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"libapparmor-perl","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"libapparmor1","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"libpam-apparmor","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"python-apparmor","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"python-libapparmor","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"python3-apparmor","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"},{"name":"python3-libapparmor","version":"2.10.95-0ubuntu2.6~14.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6~14.04.1","pocket":"security"}],"xenial":[{"name":"apparmor","version":"2.10.95-0ubuntu2.6","description":"Linux security system","is_source":true},{"name":"apparmor","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"apparmor-docs","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"apparmor-easyprof","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"apparmor-notify","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"apparmor-profiles","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"apparmor-utils","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"dh-apparmor","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"libapache2-mod-apparmor","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"libapparmor-dev","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"libapparmor-perl","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"libapparmor1","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"libpam-apparmor","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"python-apparmor","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"python-libapparmor","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"python3-apparmor","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"},{"name":"python3-libapparmor","version":"2.10.95-0ubuntu2.6","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-0ubuntu2.6","pocket":"security"}],"yakkety":[{"name":"apparmor","version":"2.10.95-4ubuntu5.3","description":"Linux security system","is_source":true},{"name":"apparmor","version":"2.10.95-4ubuntu5.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/apparmor","version_link":"https://launchpad.net/ubuntu/+source/apparmor/2.10.95-4ubuntu5.3"}]},"type":"USN","cves_ids":["CVE-2017-6507"]}]},{"id":"CVE-2017-6369","published":"2017-03-24T00:00:00","updated_at":"2025-10-13T07:17:55.262418+00:00","description":"\nInsufficient checks in the UDF subsystem in Firebird 2.5.x before 2.5.7 and\n3.0.x before 3.0.2 allow remote authenticated users to execute code by\nusing a 'system' entrypoint from fbudf.so.","ubuntu_description":"\nIt was discovered that Firebird exposed certain UDF libraries. An authenticated\nattacker could use this issue to execute arbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["http://tracker.firebirdsql.org/browse/CORE-5474","https://ubuntu.com/security/notices/USN-3929-1","https://www.cve.org/CVERecord?id=CVE-2017-6369","https://ubuntu.com/security/notices/USN-4822-1"],"bugs":[""],"patches":{"firebird2.5":[],"firebird3.0":[]},"tags":{},"packages":[{"name":"firebird2.5","source":"https://ubuntu.com/security/cve?package=firebird2.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird2.5","debian":"https://tracker.debian.org/pkg/firebird2.5","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.5.2.26540.ds4-9ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2.5.4.26856.ds4-1ubuntu0.1~esm1","component":null,"pocket":"esm-apps"}]},{"name":"firebird3.0","source":"https://ubuntu.com/security/cve?package=firebird3.0","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firebird3.0","debian":"https://tracker.debian.org/pkg/firebird3.0","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"3.0.2.32703.ds4-11ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"3.0.2.32703.ds4-11ubuntu2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"3.0.2.32703.ds4-11ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"3.0.2.32703.ds4-11ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"3.0.2.32703.ds4-11ubuntu2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.1.32609.ds4-14","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"3.0.2.32703.ds4-11ubuntu2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"3.0.2.32703.ds4-11ubuntu2","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"3.0.2.32703.ds4-11ubuntu2","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"3.0.2.32703.ds4-11ubuntu2","component":null,"pocket":"security"}]}],"notices_ids":["USN-3929-1","USN-4822-1"],"notices":[{"id":"USN-3929-1","title":"Firebird vulnerabilities","summary":"Several security issues were fixed in Firebird.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2019-04-02T14:36:46.964566","description":"It was discovered that Firebird incorrectly handled certain malformed\npackets. A remote attacker could possibly use this issue with a specially\ncrafted network packet to cause Firebird to crash, resulting in a denial of\nservice.\n(CVE-2014-9323)\n\nIt was discovered that Firebird incorrectly handled certain UDF libraries.\nA remote attacker could possibly use this issue to execute arbitrary code.\n(CVE-2017-6369)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"firebird2.5","version":"2.5.2.26540.ds4-9ubuntu1.1","description":"A full-featured, open source SQL database derived from Borland InterBase 6.0","is_source":true},{"name":"firebird-dev","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"firebird2.5-classic","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"firebird2.5-classic-common","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"firebird2.5-common","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"firebird2.5-common-doc","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"firebird2.5-doc","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"firebird2.5-examples","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"firebird2.5-server-common","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"firebird2.5-super","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"firebird2.5-superclassic","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"libfbclient2","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"libfbembed2.5","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"},{"name":"libib-util","version":"2.5.2.26540.ds4-9ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":"https://launchpad.net/ubuntu/+source/firebird2.5/2.5.2.26540.ds4-9ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2014-9323","CVE-2017-6369"]},{"id":"USN-4822-1","title":"Firebird vulnerability","summary":"\nFirebird could be made to crash or run programs if it received specially\ncrafted input.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2021-03-15T22:00:01.987479","description":"It was discovered that Firebird exposed certain UDF libraries. An\nauthenticated attacker could use this vulnerability to cause a denial of service\n(crash) or possibly execute arbitrary code.\n\n","is_hidden":false,"release_packages":{"xenial":[{"name":"firebird2.5","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","description":"A full-featured, open source SQL database derived from Borland InterBase 6.0","is_source":true},{"name":"firebird2.5-doc","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"libfbclient2","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"firebird2.5-classic-common","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"libfbembed2.5","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"firebird2.5-server-common","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"firebird2.5-common","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"firebird2.5-classic","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"firebird2.5-common-doc","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"firebird2.5-superclassic","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"libib-util","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"firebird-dev","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"firebird2.5-examples","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"},{"name":"firebird2.5-super","version":"2.5.4.26856.ds4-1ubuntu0.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/firebird2.5","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2017-6369"]}]},{"id":"CVE-2016-7797","published":"2017-03-24T00:00:00","updated_at":"2025-08-25T22:11:05.081291+00:00","description":"\nPacemaker before 1.1.15, when using pacemaker remote, might allow remote\nattackers to cause a denial of service (node disconnection) via an\nunauthenticated connection.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 1.1.12"}],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://ubuntu.com/security/notices/USN-3462-1","https://www.cve.org/CVERecord?id=CVE-2016-7797"],"bugs":["http://bugs.clusterlabs.org/show_bug.cgi?id=5269"],"patches":{"pacemaker":["upstream: https://github.com/ClusterLabs/pacemaker/commit/5ec24a26"]},"tags":{},"packages":[{"name":"pacemaker","source":"https://ubuntu.com/security/cve?package=pacemaker","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pacemaker","debian":"https://tracker.debian.org/pkg/pacemaker","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.1.15~rc3-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.1.14-2ubuntu1.2","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.1.15-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.1.15-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1.1.15-1ubuntu2","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [1.1.10+git20130802-1ubuntu2.3]","component":null,"pocket":"security"}]}],"notices_ids":["USN-3462-1"],"notices":[{"id":"USN-3462-1","title":"Pacemaker vulnerabilities","summary":"Several security issues were fixed in Pacemaker.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-10-24T13:27:05.512179","description":"Jan Pokorný and Alain Moulle discovered that Pacemaker incorrectly handled\nthe IPC interface. A local attacker could possibly use this issue to\nexecute arbitrary code with root privileges. (CVE-2016-7035)\n\nAlain Moulle discovered that Pacemaker incorrectly handled authentication.\nA remote attacker could possibly use this issue to shut down connections,\nleading to a denial of service. This issue only affected Ubuntu 16.04 LTS.\n(CVE-2016-7797)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"pacemaker","version":"1.1.10+git20130802-1ubuntu2.4","description":"Cluster resource manager","is_source":true},{"name":"libcib3","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libcib3-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libcrmcluster4","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libcrmcluster4-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libcrmcommon3","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libcrmcommon3-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libcrmservice1","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libcrmservice1-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"liblrmd1","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"liblrmd1-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libpe-rules2","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libpe-rules2-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libpe-status4","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libpe-status4-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libpengine4","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libpengine4-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libstonithd2","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libstonithd2-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libtransitioner2","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"libtransitioner2-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"pacemaker","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"pacemaker-cli-utils","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"pacemaker-dev","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"},{"name":"pacemaker-remote","version":"1.1.10+git20130802-1ubuntu2.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.10+git20130802-1ubuntu2.4","pocket":"security"}],"xenial":[{"name":"pacemaker","version":"1.1.14-2ubuntu1.2","description":"Cluster resource manager","is_source":true},{"name":"libcib-dev","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libcib4","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libcrmcluster-dev","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libcrmcluster4","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libcrmcommon-dev","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libcrmcommon3","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libcrmservice-dev","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libcrmservice3","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"liblrmd-dev","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"liblrmd1","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libpe-rules2","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libpe-status10","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libpengine-dev","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libpengine10","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libstonithd-dev","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libstonithd2","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"libtransitioner2","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"pacemaker","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"pacemaker-cli-utils","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"pacemaker-common","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"pacemaker-doc","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"pacemaker-remote","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"},{"name":"pacemaker-resource-agents","version":"1.1.14-2ubuntu1.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/pacemaker","version_link":"https://launchpad.net/ubuntu/+source/pacemaker/1.1.14-2ubuntu1.2","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-7035","CVE-2016-7797"]}]},{"id":"CVE-2016-10269","published":"2017-03-24T00:00:00","updated_at":"2025-08-25T21:53:14.796749+00:00","description":"\nLibTIFF 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1,\n4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6 and 4.0.7 allows remote\nattackers to cause a denial of service (heap-based buffer over-read) or\npossibly have unspecified other impact via a crafted TIFF image, related to\n\"READ of size 512\" and libtiff/tif_unix.c:340:2.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"this will not be fixed in precise/esm"}],"codename":null,"priority":"negligible","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-heap-based-buffer-overflow/","https://ubuntu.com/security/notices/USN-3602-1","https://www.cve.org/CVERecord?id=CVE-2016-10269"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2604"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/1044b43637fa7f70fb19b93593777b78bd20da86"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.7-5","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-3602-1"],"notices":[{"id":"USN-3602-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-20T17:20:33.729345","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.8","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.3","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10266","CVE-2016-10267","CVE-2016-10268","CVE-2016-10269","CVE-2016-10371","CVE-2017-10688","CVE-2017-11335","CVE-2017-12944","CVE-2017-13726","CVE-2017-13727","CVE-2017-18013","CVE-2017-7592","CVE-2017-7593","CVE-2017-7594","CVE-2017-7595","CVE-2017-7596","CVE-2017-7597","CVE-2017-7598","CVE-2017-7599","CVE-2017-7600","CVE-2017-7601","CVE-2017-7602","CVE-2017-9403","CVE-2017-9404","CVE-2017-9815","CVE-2017-9936","CVE-2018-5784"]}]},{"id":"CVE-2016-10268","published":"2017-03-24T00:00:00","updated_at":"2025-08-25T21:53:14.796749+00:00","description":"\ntools/tiffcp.c in LibTIFF 4.0.7 allows remote attackers to cause a denial\nof service (integer underflow and heap-based buffer under-read) or possibly\nhave unspecified other impact via a crafted TIFF image, related to \"READ of\nsize 78490\" and libtiff/tif_unix.c:115:23.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-heap-based-buffer-overflow/","https://ubuntu.com/security/notices/USN-3602-1","https://www.cve.org/CVERecord?id=CVE-2016-10268"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2598"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/5397a417e61258c69209904e652a1f409ec3b9df"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.7-5","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-3602-1"],"notices":[{"id":"USN-3602-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-20T17:20:33.729345","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.8","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.3","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10266","CVE-2016-10267","CVE-2016-10268","CVE-2016-10269","CVE-2016-10371","CVE-2017-10688","CVE-2017-11335","CVE-2017-12944","CVE-2017-13726","CVE-2017-13727","CVE-2017-18013","CVE-2017-7592","CVE-2017-7593","CVE-2017-7594","CVE-2017-7595","CVE-2017-7596","CVE-2017-7597","CVE-2017-7598","CVE-2017-7599","CVE-2017-7600","CVE-2017-7601","CVE-2017-7602","CVE-2017-9403","CVE-2017-9404","CVE-2017-9815","CVE-2017-9936","CVE-2018-5784"]}]},{"id":"CVE-2016-10267","published":"2017-03-24T00:00:00","updated_at":"2025-08-25T21:53:10.076687+00:00","description":"\nLibTIFF 4.0.7 allows remote attackers to cause a denial of service\n(divide-by-zero error and application crash) via a crafted TIFF image,\nrelated to libtiff/tif_ojpeg.c:816:8.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-divide-by-zero/","https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-divide-by-zero","https://ubuntu.com/security/notices/USN-3602-1","https://www.cve.org/CVERecord?id=CVE-2016-10267"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2611"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/43bc256d8ae44b92d2734a3c5bc73957a4d7c1ec"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.7-5","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-3602-1"],"notices":[{"id":"USN-3602-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-20T17:20:33.729345","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.8","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.3","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10266","CVE-2016-10267","CVE-2016-10268","CVE-2016-10269","CVE-2016-10371","CVE-2017-10688","CVE-2017-11335","CVE-2017-12944","CVE-2017-13726","CVE-2017-13727","CVE-2017-18013","CVE-2017-7592","CVE-2017-7593","CVE-2017-7594","CVE-2017-7595","CVE-2017-7596","CVE-2017-7597","CVE-2017-7598","CVE-2017-7599","CVE-2017-7600","CVE-2017-7601","CVE-2017-7602","CVE-2017-9403","CVE-2017-9404","CVE-2017-9815","CVE-2017-9936","CVE-2018-5784"]}]},{"id":"CVE-2016-10266","published":"2017-03-24T00:00:00","updated_at":"2025-08-25T21:53:10.076687+00:00","description":"\nLibTIFF 4.0.7 allows remote attackers to cause a denial of service\n(divide-by-zero error and application crash) via a crafted TIFF image,\nrelated to libtiff/tif_read.c:351:22.","ubuntu_description":"","notes":[],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/01/01/libtiff-multiple-divide-by-zero","https://ubuntu.com/security/notices/USN-3602-1","https://www.cve.org/CVERecord?id=CVE-2016-10266"],"bugs":["http://bugzilla.maptools.org/show_bug.cgi?id=2596"],"patches":{"tiff":["upstream: https://github.com/vadz/libtiff/commit/438274f938e046d33cb0e1230b41da32ffe223e1"]},"tags":{},"packages":[{"name":"tiff","source":"https://ubuntu.com/security/cve?package=tiff","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=tiff","debian":"https://tracker.debian.org/pkg/tiff","statuses":[{"release_codename":"artful","status":"not-affected","description":"4.0.7-5","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"4.0.3-7ubuntu0.8","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.0.7-2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"4.0.6-1ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.0.7-5","component":null,"pocket":"security"}]}],"notices_ids":["USN-3602-1"],"notices":[{"id":"USN-3602-1","title":"LibTIFF vulnerabilities","summary":"LibTIFF could be made to crash or run programs as your login if it opened a\nspecially crafted file.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2018-03-20T17:20:33.729345","description":"It was discovered that LibTIFF incorrectly handled certain malformed\nimages. If a user or automated system were tricked into opening a specially\ncrafted image, a remote attacker could crash the application, leading to a\ndenial of service, or possibly execute arbitrary code with user privileges.\n","is_hidden":false,"release_packages":{"trusty":[{"name":"tiff","version":"4.0.3-7ubuntu0.8","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff-tools","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff4-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-alt-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"},{"name":"libtiffxx5","version":"4.0.3-7ubuntu0.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.3-7ubuntu0.8","pocket":"security"}],"xenial":[{"name":"tiff","version":"4.0.6-1ubuntu0.3","description":"Tag Image File Format (TIFF) library","is_source":true},{"name":"libtiff-doc","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-opengl","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff-tools","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiff5-dev","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"},{"name":"libtiffxx5","version":"4.0.6-1ubuntu0.3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/tiff","version_link":"https://launchpad.net/ubuntu/+source/tiff/4.0.6-1ubuntu0.3","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10266","CVE-2016-10267","CVE-2016-10268","CVE-2016-10269","CVE-2016-10371","CVE-2017-10688","CVE-2017-11335","CVE-2017-12944","CVE-2017-13726","CVE-2017-13727","CVE-2017-18013","CVE-2017-7592","CVE-2017-7593","CVE-2017-7594","CVE-2017-7595","CVE-2017-7596","CVE-2017-7597","CVE-2017-7598","CVE-2017-7599","CVE-2017-7600","CVE-2017-7601","CVE-2017-7602","CVE-2017-9403","CVE-2017-9404","CVE-2017-9815","CVE-2017-9936","CVE-2018-5784"]}]},{"id":"CVE-2016-10149","published":"2017-03-24T00:00:00","updated_at":"2025-08-25T21:52:37.150045+00:00","description":"\nXML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows\nremote attackers to read arbitrary files via a crafted SAML XML request or\nresponse.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/rohe/pysaml2/pull/379","https://ubuntu.com/security/notices/USN-3402-1","https://www.cve.org/CVERecord?id=CVE-2016-10149"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=850716"],"patches":{"python-pysaml2":["upstream: https://github.com/rohe/pysaml2/commit/6e09a25d9b4b7aa7a506853210a9a14100b8bc9b"]},"tags":{},"packages":[{"name":"python-pysaml2","source":"https://ubuntu.com/security/cve?package=python-pysaml2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python-pysaml2","debian":"https://tracker.debian.org/pkg/python-pysaml2","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.0.0-5","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"3.0.0-3ubuntu1.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"3.0.0-3ubuntu1.17.04.1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3402-1"],"notices":[{"id":"USN-3402-1","title":"PySAML2 vulnerability","summary":"The system could be made to expose sensitive information.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2017-08-24T12:02:11.945077","description":"It was discovered that PySAML2 incorrectly handled certain\nSAML XML requests and responses. A remote attacker could use\nthis issue to read arbitrary files.\n","is_hidden":false,"release_packages":{"xenial":[{"name":"python-pysaml2","version":"3.0.0-3ubuntu1.16.04.1","description":"Pure python implementation of SAML2","is_source":true},{"name":"python-pysaml2","version":"3.0.0-3ubuntu1.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.16.04.1","pocket":"security"},{"name":"python-pysaml2-doc","version":"3.0.0-3ubuntu1.16.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.16.04.1","pocket":"security"},{"name":"python3-pysaml2","version":"3.0.0-3ubuntu1.16.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.16.04.1","pocket":"security"}],"zesty":[{"name":"python-pysaml2","version":"3.0.0-3ubuntu1.17.04.1","description":"Pure python implementation of SAML2","is_source":true},{"name":"python-pysaml2","version":"3.0.0-3ubuntu1.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.17.04.1"},{"name":"python3-pysaml2","version":"3.0.0-3ubuntu1.17.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/python-pysaml2","version_link":"https://launchpad.net/ubuntu/+source/python-pysaml2/3.0.0-3ubuntu1.17.04.1"}]},"type":"USN","cves_ids":["CVE-2016-10149"]}]},{"id":"CVE-2017-7246","published":"2017-03-23T21:59:00","updated_at":"2025-08-25T22:37:24.683749+00:00","description":"\nStack-based buffer overflow in the pcre32_copy_substring function in\npcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a\ndenial of service (WRITE of size 268) or possibly have unspecified other\nimpact via a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is actually an issue in the pcretest binary, which we\ndon't ship in Ubuntu\nsame commit as CVE-2017-7245"}],"codename":null,"priority":"negligible","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/03/20/libpcre-two-stack-based-buffer-overflow-write-in-pcre32_copy_substring-pcre_get-c/","https://www.cve.org/CVERecord?id=CVE-2017-7246"],"bugs":["https://bugs.exim.org/show_bug.cgi?id=2057","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858679"],"patches":{"pcre3":["upstream: http://vcs.pcre.org/pcre?view=revision&revision=1691"]},"tags":{},"packages":[{"name":"pcre3","source":"https://ubuntu.com/security/cve?package=pcre3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcre3","debian":"https://tracker.debian.org/pkg/pcre3","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7245","published":"2017-03-23T21:59:00","updated_at":"2025-08-25T22:37:18.497515+00:00","description":"\nStack-based buffer overflow in the pcre32_copy_substring function in\npcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a\ndenial of service (WRITE of size 4) or possibly have unspecified other\nimpact via a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"This is actually an issue in the pcretest binary, which we\ndon't ship in Ubuntu"}],"codename":null,"priority":"negligible","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/03/20/libpcre-two-stack-based-buffer-overflow-write-in-pcre32_copy_substring-pcre_get-c/","https://www.cve.org/CVERecord?id=CVE-2017-7245"],"bugs":["https://bugs.exim.org/show_bug.cgi?id=2055","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858678"],"patches":{"pcre3":["upstream: https://vcs.pcre.org/pcre?view=revision&revision=1691"]},"tags":{},"packages":[{"name":"pcre3","source":"https://ubuntu.com/security/cve?package=pcre3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcre3","debian":"https://tracker.debian.org/pkg/pcre3","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"disco","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-7244","published":"2017-03-23T21:59:00","updated_at":"2025-08-25T22:37:18.497515+00:00","description":"\nThe _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40\nallows remote attackers to cause a denial of service (invalid memory read)\nvia a crafted file.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"pcre32 support enabled only in pcre3/1:8.35-4\nsame commit as CVE-2017-7186"},{"author":"ccdm94","note":"in xenial, this CVE was patched together with CVE-2017-7186,\nsince the fixes are the same, i.e. USN-5665-1 fixes this\nissue without mentioning this CVE."}],"codename":null,"priority":"low","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/03/20/libpcre-invalid-memory-read-in-_pcre32_xclass-pcre_xclass-c/","https://www.cve.org/CVERecord?id=CVE-2017-7244"],"bugs":["https://bugs.exim.org/show_bug.cgi?id=2054","https://bugs.exim.org/show_bug.cgi?id=2052","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=858683"],"patches":{"pcre3":["upstream: https://vcs.pcre.org/pcre?view=revision&revision=1688"]},"tags":{},"packages":[{"name":"pcre3","source":"https://ubuntu.com/security/cve?package=pcre3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pcre3","debian":"https://tracker.debian.org/pkg/pcre3","statuses":[{"release_codename":"hirsute","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2:8.39-3","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"2:8.38-3.1ubuntu0.1~esm2","component":null,"pocket":"esm-infra"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2:8.39-3","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8628","published":"2017-03-23T20:59:00","updated_at":"2025-08-25T21:48:19.636244+00:00","description":"\nThe (1) Special:MyPage, (2) Special:MyTalk, (3) Special:MyContributions,\n(4) Special:MyUploads, and (5) Special:AllMyUploads pages in MediaWiki\nbefore 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and 1.26.x\nbefore 1.26.1 allow remote attackers to obtain sensitive user login\ninformation via crafted links combined with page view statistics.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T109724","https://www.cve.org/CVERecord?id=CVE-2015-8628"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.27.4-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.25.5-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8627","published":"2017-03-23T20:59:00","updated_at":"2025-08-25T21:48:19.636244+00:00","description":"\nMediaWiki before 1.23.12, 1.24.x before 1.24.5, 1.25.x before 1.25.4, and\n1.26.x before 1.26.1 do not properly normalize IP addresses containing\nzero-padded octets, which might allow remote attackers to bypass intended\naccess restrictions by using an IP address that was not supposed to have\nbeen allowed.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T97897","https://www.cve.org/CVERecord?id=CVE-2015-8627"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.27.4-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.25.5-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8626","published":"2017-03-23T20:59:00","updated_at":"2025-08-25T21:48:19.636244+00:00","description":"\nThe User::randomPassword function in MediaWiki before 1.23.12, 1.24.x\nbefore 1.24.5, 1.25.x before 1.25.4, and 1.26.x before 1.26.1 generates\npasswords smaller than $wgMinimalPasswordLength, which makes it easier for\nremote attackers to obtain access via a brute-force attack.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://phabricator.wikimedia.org/T115522","https://www.cve.org/CVERecord?id=CVE-2015-8626"],"bugs":[""],"patches":{"mediawiki":[]},"tags":{},"packages":[{"name":"mediawiki","source":"https://ubuntu.com/security/cve?package=mediawiki","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mediawiki","debian":"https://tracker.debian.org/pkg/mediawiki","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:1.27.4-3","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:1.31.1-3","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1:1.25.5-1","component":null,"pocket":"security"},{"release_codename":"vivid","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty/esm was DNE [trusty was needed]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":57680,"limit":20,"total_results":79316}