{"cves":[{"id":"CVE-2017-5505","published":"2017-03-16T15:59:00","updated_at":"2025-08-25T22:34:38.850215+00:00","description":"\nThe jas_matrix_asl function in jas_seq.c in JasPer 1.900.27 allows remote\nattackers to cause a denial of service (invalid memory read and crash) via\na crafted image.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 1.900.25"}],"codename":null,"priority":"negligible","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://blogs.gentoo.org/ago/2017/01/16/jasper-invalid-memory-read-in-jas_matrix_asl-jas_seq-c","https://www.cve.org/CVERecord?id=CVE-2017-5505"],"bugs":["https://github.com/mdadams/jasper/issues/88"],"patches":{"jasper":[]},"tags":{},"packages":[{"name":"jasper","source":"https://ubuntu.com/security/cve?package=jasper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jasper","debian":"https://tracker.debian.org/pkg/jasper","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10187","published":"2017-03-16T15:59:00","updated_at":"2025-08-26T11:53:34.843055+00:00","description":"\nThe E-book viewer in calibre before 2.75 allows remote attackers to read\narbitrary files via a crafted epub file with JavaScript.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/01/29/8","https://www.cve.org/CVERecord?id=CVE-2016-10187"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853004"],"patches":{"calibre":["upstream: https://github.com/kovidgoyal/calibre/commit/3a89718664cb8cce0449d1758eee585ed0d0433c"]},"tags":{},"packages":[{"name":"calibre","source":"https://ubuntu.com/security/cve?package=calibre","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=calibre","debian":"https://tracker.debian.org/pkg/calibre","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2.75.1+dfsg-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was needed","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"2.75.1+dfsg-1build1~1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2015-8981","published":"2017-03-16T15:59:00","updated_at":"2025-08-18T17:04:52.845006+00:00","description":"\nHeap-based buffer overflow in the PdfParser::ReadXRefSubsection function in\nbase/PdfParser.cpp in PoDoFo allows attackers to have unspecified impact\nvia vectors related to m_offsets.size.","ubuntu_description":"\nHanno Böck discovered that PoDoFo mishandled certain crafted PDF files, resulting\nin a heap-based buffer overflow. If PoDoFo were to open a malicious PDF, an\nattacker could cause PoDoFo to crash or possibly execute arbitrary code.","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://marc.info/?l=oss-security&m=148601605717859&w=2","https://www.cve.org/CVERecord?id=CVE-2015-8981"],"bugs":[""],"patches":{"libpodofo":["upstream: http://sourceforge.net/p/podofo/code/1672"]},"tags":{},"packages":[{"name":"libpodofo","source":"https://ubuntu.com/security/cve?package=libpodofo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=libpodofo","debian":"https://tracker.debian.org/pkg/libpodofo","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"impish","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"0.9.0-1.2ubuntu0.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"kinetic","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"oracular","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"0.9.4-6","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6381","published":"2017-03-16T14:59:00","updated_at":"2025-08-26T12:01:03.987607+00:00","description":"\nA 3rd party development library including with Drupal 8 development\ndependencies is vulnerable to remote code execution. This is mitigated by\nthe default .htaccess protection against PHP execution, and the fact that\nComposer development dependencies aren't normal installed. You might be\nvulnerable to this if you are running a version of Drupal before 8.2.2. To\nbe sure you aren't vulnerable, you can remove the <siteroot>/vendor/phpunit\ndirectory from your production deployments","ubuntu_description":"","notes":[{"author":"ratliff","note":"Ubuntu doesn't package drupal8 and it is unclear whether this\nvulnerability impacts drupal7, it needs a bit more investigation"}],"codename":null,"priority":"medium","cvss3":8.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.drupal.org/SA-2017-001","https://www.cve.org/CVERecord?id=CVE-2017-6381"],"bugs":[""],"patches":{"drupal7":[]},"tags":{},"packages":[{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"oracular","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6379","published":"2017-03-16T14:59:00","updated_at":"2025-08-25T22:36:07.180418+00:00","description":"\nSome administrative paths in Drupal 8.2.x before 8.2.7 did not include\nprotection for CSRF. This would allow an attacker to disable some blocks on\na site. This issue is mitigated by the fact that users would have to know\nthe block ID.","ubuntu_description":"\nratliff> Ubuntu doesn't currently package drupal8 and it is unclear whether\n this issue is applicable back to drupal7","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.drupal.org/SA-2017-001","https://www.cve.org/CVERecord?id=CVE-2017-6379"],"bugs":[""],"patches":{"drupal7":[]},"tags":{},"packages":[{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"not-affected","description":"Drupal 8.2.x","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"Drupal 8.2.x","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"Drupal 8.2.x","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6377","published":"2017-03-16T14:59:00","updated_at":"2025-08-25T22:36:07.180418+00:00","description":"\nWhen adding a private file via the editor in Drupal 8.2.x before 8.2.7, the\neditor will not correctly check access for the file being attached,\nresulting in an access bypass.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.drupal.org/SA-2017-001","https://www.cve.org/CVERecord?id=CVE-2017-6377"],"bugs":[""],"patches":{"drupal7":[]},"tags":{},"packages":[{"name":"drupal7","source":"https://ubuntu.com/security/cve?package=drupal7","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=drupal7","debian":"https://tracker.debian.org/pkg/drupal7","statuses":[{"release_codename":"upstream","status":"not-affected","description":"Drupal 8.2.x","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"Drupal 8.2.x","component":null,"pocket":"security"},{"release_codename":"kinetic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"impish","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"lunar","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"Drupal 8.2.x","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10247","published":"2017-03-16T14:59:00","updated_at":"2025-08-25T21:53:05.475587+00:00","description":"\nBuffer overflow in the my_getline function in jstest_main.c in Mujstest in\nArtifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a\ndenial of service (out-of-bounds write) via a crafted file.","ubuntu_description":"","notes":[{"author":"ratliff","note":"test program not included in binary packages"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/10/16/19","https://www.cve.org/CVERecord?id=CVE-2016-10247"],"bugs":[""],"patches":{"mupdf":[]},"tags":{},"packages":[{"name":"mupdf","source":"https://ubuntu.com/security/cve?package=mupdf","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mupdf","debian":"https://tracker.debian.org/pkg/mupdf","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not shipped","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"code not shipped","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not shipped]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-10246","published":"2017-03-16T14:59:00","updated_at":"2025-08-25T21:53:05.475587+00:00","description":"\nBuffer overflow in the main function in jstest_main.c in Mujstest in\nArtifex Software, Inc. MuPDF before 1.10 allows remote attackers to cause a\ndenial of service (out-of-bounds write) via a crafted file.","ubuntu_description":"","notes":[{"author":"ratliff","note":"test program not included in binary packages"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2016/10/16/20","https://www.cve.org/CVERecord?id=CVE-2016-10246"],"bugs":[""],"patches":{"mupdf":[]},"tags":{},"packages":[{"name":"mupdf","source":"https://ubuntu.com/security/cve?package=mupdf","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mupdf","debian":"https://tracker.debian.org/pkg/mupdf","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not shipped","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"code not shipped","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not shipped]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6951","published":"2017-03-16T00:00:00","updated_at":"2026-07-04T07:43:48.105124+00:00","description":"\nThe keyring_search_aux function in security/keys/keyring.c in the Linux\nkernel through 3.14.79 allows local users to cause a denial of service\n(NULL pointer dereference and OOPS) via a request_key system call for the\n\"dead\" type.","ubuntu_description":"\nIt was discovered that the keyring implementation in the Linux kernel did\nnot properly restrict searches for dead keys. A local attacker could use\nthis to cause a denial of service (system crash).","notes":[{"author":"sbeattie","note":"partially fixed by c06cfb08b88dfbe13be44a69ae2fdc3a7c902d81\nthough see http://www.spinics.net/lists/keyrings/msg01883.html\nin the Red Hat bug report, David Howells has an alternate fix\nthat may be more appropriate for live-patching than\nc06cfb08b88dfbe13be44a69ae2fdc3a7c902d81 :\nhttps://bugzilla.redhat.com/attachment.cgi?id=1268882"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.spinics.net/lists/keyrings/msg01845.html","http://www.spinics.net/lists/keyrings/msg01846.html","http://www.spinics.net/lists/keyrings/msg01849.html","https://ubuntu.com/security/notices/USN-3422-1","https://ubuntu.com/security/notices/USN-3422-2","https://www.cve.org/CVERecord?id=CVE-2017-6951"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1433252"],"patches":{"linux":["break-fix: - c06cfb08b88dfbe13be44a69ae2fdc3a7c902d81|c1644fe041ebaf6519f6809146a77c3ead9193af"],"linux-ti-omap4":[],"linux-linaro-omap":[],"linux-linaro-shared":[],"linux-linaro-vexpress":[],"linux-qcm-msm":[],"linux-armadaxp":[],"linux-lts-quantal":[],"linux-lts-raring":[],"linux-lts-saucy":[],"linux-lts-trusty":[],"linux-goldfish":[],"linux-grouper":[],"linux-maguro":[],"linux-mako":[],"linux-manta":[],"linux-flo":[],"linux-raspi2":[],"linux-lts-utopic":[],"linux-lts-vivid":[],"linux-lts-wily":[],"linux-lts-xenial":[],"linux-snapdragon":[],"linux-aws":[],"linux-hwe":[],"linux-hwe-edge":[],"linux-gke":[],"linux-azure":[],"linux-gcp":[],"linux-kvm":[],"linux-euclid":[],"linux-oem":[],"linux-hwe-5.4":[],"linux-hwe-5.15":[],"linux-hwe-6.8":[],"linux-hwe-6.11":[],"linux-hwe-6.14":[],"linux-aws-5.4":[],"linux-aws-5.15":[],"linux-aws-6.8":[],"linux-aws-6.14":[],"linux-aws-hwe":[],"linux-azure-4.15":[],"linux-azure-5.4":[],"linux-azure-5.15":[],"linux-azure-6.8":[],"linux-azure-6.11":[],"linux-azure-fde":[],"linux-azure-fde-5.15":[],"linux-azure-nvidia":[],"linux-bluefield":[],"linux-fips":[],"linux-aws-fips":[],"linux-azure-fips":[],"linux-gcp-fips":[],"linux-gcp-4.15":[],"linux-gcp-5.4":[],"linux-gcp-5.15":[],"linux-gcp-6.8":[],"linux-gcp-6.11":[],"linux-gcp-6.14":[],"linux-gkeop":[],"linux-ibm":[],"linux-ibm-5.4":[],"linux-ibm-5.15":[],"linux-ibm-6.8":[],"linux-intel":[],"linux-intel-iotg":[],"linux-intel-iotg-5.15":[],"linux-iot":[],"linux-intel-iot-realtime":[],"linux-lowlatency":[],"linux-lowlatency-hwe-5.15":[],"linux-lowlatency-hwe-6.8":[],"linux-lowlatency-hwe-6.11":[],"linux-nvidia":[],"linux-nvidia-6.8":[],"linux-nvidia-lowlatency":[],"linux-nvidia-tegra":[],"linux-nvidia-tegra-5.15":[],"linux-nvidia-tegra-igx":[],"linux-oracle":[],"linux-oracle-5.4":[],"linux-oracle-5.15":[],"linux-oracle-6.8":[],"linux-oracle-6.14":[],"linux-oem-6.8":[],"linux-oem-6.11":[],"linux-oem-6.14":[],"linux-raspi":[],"linux-raspi-5.4":[],"linux-raspi-realtime":[],"linux-realtime":[],"linux-riscv":[],"linux-riscv-5.15":[],"linux-riscv-6.8":[],"linux-riscv-6.14":[],"linux-xilinx-zynqmp":[],"linux-nvidia-6.11":[],"linux-realtime-6.8":[],"linux-realtime-6.14":[]},"tags":{"linux":["binary-exclude:linux-libc-dev"],"linux-armadaxp":["not-ue"],"linux-lts-quantal":["not-ue"],"linux-lts-saucy":["not-ue"]},"packages":[{"name":"linux-aws-fips","source":"https://ubuntu.com/security/cve?package=linux-aws-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-fips","debian":"https://tracker.debian.org/pkg/linux-aws-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1052.57+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-2000.4","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips2","component":null,"pocket":"fips"}]},{"name":"linux-azure-fips","source":"https://ubuntu.com/security/cve?package=linux-azure-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-fips","debian":"https://tracker.debian.org/pkg/linux-azure-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1058.66+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1022.22+fips1","component":null,"pocket":"fips"}]},{"name":"linux-gcp-fips","source":"https://ubuntu.com/security/cve?package=linux-gcp-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-fips","debian":"https://tracker.debian.org/pkg/linux-gcp-fips","statuses":[{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1048.56+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1021.21+fips1","component":null,"pocket":"fips"}]},{"name":"linux","source":"https://ubuntu.com/security/cve?package=linux","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux","debian":"https://tracker.debian.org/pkg/linux","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.10.0-19.21","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"3.13.0-132.181","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-21.37","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-22.24","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-2.16","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-16.19","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-9.12","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-19.19","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8","component":null,"pocket":"security"}]},{"name":"linux-armadaxp","source":"https://ubuntu.com/security/cve?package=linux-armadaxp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-armadaxp","debian":"https://tracker.debian.org/pkg/linux-armadaxp","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-aws","source":"https://ubuntu.com/security/cve?package=linux-aws","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws","debian":"https://tracker.debian.org/pkg/linux-aws","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-1002.2","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.10","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1008.8","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-aws-5.15","source":"https://ubuntu.com/security/cve?package=linux-aws-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.15","debian":"https://tracker.debian.org/pkg/linux-aws-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.19~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-aws-5.4","source":"https://ubuntu.com/security/cve?package=linux-aws-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-5.4","debian":"https://tracker.debian.org/pkg/linux-aws-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1020.20~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-aws-6.14","source":"https://ubuntu.com/security/cve?package=linux-aws-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.14","debian":"https://tracker.debian.org/pkg/linux-aws-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-aws-6.8","source":"https://ubuntu.com/security/cve?package=linux-aws-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-6.8","debian":"https://tracker.debian.org/pkg/linux-aws-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1009.9~22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-aws-hwe","source":"https://ubuntu.com/security/cve?package=linux-aws-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-aws-hwe","debian":"https://tracker.debian.org/pkg/linux-aws-hwe","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1031.33~16.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-azure","source":"https://ubuntu.com/security/cve?package=linux-azure","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure","debian":"https://tracker.debian.org/pkg/linux-azure","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.15.0-1023.24~14.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.11.0-1015.15","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"superseded by linux-azure-5.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1006.6","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1006.7","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"}]},{"name":"linux-azure-4.15","source":"https://ubuntu.com/security/cve?package=linux-azure-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-4.15","debian":"https://tracker.debian.org/pkg/linux-azure-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1082.92","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-azure-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.8~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-azure-5.4","source":"https://ubuntu.com/security/cve?package=linux-azure-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-5.4","debian":"https://tracker.debian.org/pkg/linux-azure-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1022.22~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-azure-6.11","source":"https://ubuntu.com/security/cve?package=linux-azure-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.11","debian":"https://tracker.debian.org/pkg/linux-azure-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-azure-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-azure-6.8","source":"https://ubuntu.com/security/cve?package=linux-azure-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-6.8","debian":"https://tracker.debian.org/pkg/linux-azure-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-azure-fde","source":"https://ubuntu.com/security/cve?package=linux-azure-fde","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde","debian":"https://tracker.debian.org/pkg/linux-azure-fde","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1019.24.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.14.0-1012.12","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1041.48","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-azure-fde-5.15","source":"https://ubuntu.com/security/cve?package=linux-azure-fde-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-fde-5.15","debian":"https://tracker.debian.org/pkg/linux-azure-fde-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support, was needed","component":null,"pocket":"security"}]},{"name":"linux-azure-nvidia","source":"https://ubuntu.com/security/cve?package=linux-azure-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-azure-nvidia","debian":"https://tracker.debian.org/pkg/linux-azure-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1013.14","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-bluefield","source":"https://ubuntu.com/security/cve?package=linux-bluefield","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-bluefield","debian":"https://tracker.debian.org/pkg/linux-bluefield","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1011.14","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-euclid","source":"https://ubuntu.com/security/cve?package=linux-euclid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-euclid","debian":"https://tracker.debian.org/pkg/linux-euclid","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-fips","source":"https://ubuntu.com/security/cve?package=linux-fips","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-fips","debian":"https://tracker.debian.org/pkg/linux-fips","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-92.102+fips1","component":null,"pocket":"fips-updates"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1011.12","component":null,"pocket":"fips"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.8","component":null,"pocket":"fips"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1001.1","component":null,"pocket":"fips"}]},{"name":"linux-flo","source":"https://ubuntu.com/security/cve?package=linux-flo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-flo","debian":"https://tracker.debian.org/pkg/linux-flo","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gcp","source":"https://ubuntu.com/security/cve?package=linux-gcp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp","debian":"https://tracker.debian.org/pkg/linux-gcp","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.10.0-1004.4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"superseded by linux-gcp-5.3","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1005.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1003.3","component":null,"pocket":"security"}]},{"name":"linux-gcp-4.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-4.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-4.15","debian":"https://tracker.debian.org/pkg/linux-gcp-4.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1071.81","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.15","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.15","debian":"https://tracker.debian.org/pkg/linux-gcp-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1006.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-gcp-5.4","source":"https://ubuntu.com/security/cve?package=linux-gcp-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-5.4","debian":"https://tracker.debian.org/pkg/linux-gcp-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.11","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.11","debian":"https://tracker.debian.org/pkg/linux-gcp-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-gcp-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.14","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.14","debian":"https://tracker.debian.org/pkg/linux-gcp-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-gcp-6.8","source":"https://ubuntu.com/security/cve?package=linux-gcp-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gcp-6.8","debian":"https://tracker.debian.org/pkg/linux-gcp-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1010.11~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-gke","source":"https://ubuntu.com/security/cve?package=linux-gke","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gke","debian":"https://tracker.debian.org/pkg/linux-gke","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1003.3","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-gkeop","source":"https://ubuntu.com/security/cve?package=linux-gkeop","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-gkeop","debian":"https://tracker.debian.org/pkg/linux-gkeop","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-goldfish","source":"https://ubuntu.com/security/cve?package=linux-goldfish","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-goldfish","debian":"https://tracker.debian.org/pkg/linux-goldfish","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-grouper","source":"https://ubuntu.com/security/cve?package=linux-grouper","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-grouper","debian":"https://tracker.debian.org/pkg/linux-grouper","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe","source":"https://ubuntu.com/security/cve?package=linux-hwe","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe","debian":"https://tracker.debian.org/pkg/linux-hwe","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-39.42~16.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"replaced by linux-hwe-5.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-hwe-5.4","source":"https://ubuntu.com/security/cve?package=linux-hwe-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-5.4","debian":"https://tracker.debian.org/pkg/linux-hwe-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-37.41~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"superseded by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.14","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.14","debian":"https://tracker.debian.org/pkg/linux-hwe-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-24.24~24.04.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-hwe-edge","source":"https://ubuntu.com/security/cve?package=linux-hwe-edge","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-hwe-edge","debian":"https://tracker.debian.org/pkg/linux-hwe-edge","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.8.0-36.36~16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"superseded by linux-hwe-5.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ibm","source":"https://ubuntu.com/security/cve?package=linux-ibm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm","debian":"https://tracker.debian.org/pkg/linux-ibm","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1009.9","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.15","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.15","debian":"https://tracker.debian.org/pkg/linux-ibm-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1034.37~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-ibm-5.4","source":"https://ubuntu.com/security/cve?package=linux-ibm-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm-5.4","debian":"https://tracker.debian.org/pkg/linux-ibm-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1010.11~18.04.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-ibm-6.8","source":"https://ubuntu.com/security/cve?package=linux-ibm-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ibm-6.8","debian":"https://tracker.debian.org/pkg/linux-ibm-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-intel","source":"https://ubuntu.com/security/cve?package=linux-intel","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel","debian":"https://tracker.debian.org/pkg/linux-intel","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1001.6","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-intel-iot-realtime","source":"https://ubuntu.com/security/cve?package=linux-intel-iot-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel-iot-realtime","debian":"https://tracker.debian.org/pkg/linux-intel-iot-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1021.26","component":null,"pocket":"realtime"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg","debian":"https://tracker.debian.org/pkg/linux-intel-iotg","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1004.6","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-intel-iotg-5.15","source":"https://ubuntu.com/security/cve?package=linux-intel-iotg-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-intel-iotg-5.15","debian":"https://tracker.debian.org/pkg/linux-intel-iotg-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1003.5~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-iot","source":"https://ubuntu.com/security/cve?package=linux-iot","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-iot","debian":"https://tracker.debian.org/pkg/linux-iot","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1001.3","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-kvm","source":"https://ubuntu.com/security/cve?package=linux-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-kvm","debian":"https://tracker.debian.org/pkg/linux-kvm","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1007.12","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1002.2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1004.4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1004.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-omap","source":"https://ubuntu.com/security/cve?package=linux-linaro-omap","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-linaro-omap","debian":"https://tracker.debian.org/pkg/linux-linaro-omap","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-shared","source":"https://ubuntu.com/security/cve?package=linux-linaro-shared","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-linaro-shared","debian":"https://tracker.debian.org/pkg/linux-linaro-shared","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-linaro-vexpress","source":"https://ubuntu.com/security/cve?package=linux-linaro-vexpress","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-linaro-vexpress","debian":"https://tracker.debian.org/pkg/linux-linaro-vexpress","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency","debian":"https://tracker.debian.org/pkg/linux-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-22.22","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-9.9.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-5.15","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-5.15","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-33.34~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.11","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.11","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"replaced by linux-hwe-6.14, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-lowlatency-hwe-6.8","source":"https://ubuntu.com/security/cve?package=linux-lowlatency-hwe-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lowlatency-hwe-6.8","debian":"https://tracker.debian.org/pkg/linux-lowlatency-hwe-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.2","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-lts-quantal","source":"https://ubuntu.com/security/cve?package=linux-lts-quantal","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-quantal","debian":"https://tracker.debian.org/pkg/linux-lts-quantal","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-raring","source":"https://ubuntu.com/security/cve?package=linux-lts-raring","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-raring","debian":"https://tracker.debian.org/pkg/linux-lts-raring","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-saucy","source":"https://ubuntu.com/security/cve?package=linux-lts-saucy","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-saucy","debian":"https://tracker.debian.org/pkg/linux-lts-saucy","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-trusty","source":"https://ubuntu.com/security/cve?package=linux-lts-trusty","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-trusty","debian":"https://tracker.debian.org/pkg/linux-lts-trusty","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-utopic","source":"https://ubuntu.com/security/cve?package=linux-lts-utopic","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-utopic","debian":"https://tracker.debian.org/pkg/linux-lts-utopic","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-vivid","source":"https://ubuntu.com/security/cve?package=linux-lts-vivid","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-vivid","debian":"https://tracker.debian.org/pkg/linux-lts-vivid","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [3.19.0-18.18~14.04.1]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-wily","source":"https://ubuntu.com/security/cve?package=linux-lts-wily","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-wily","debian":"https://tracker.debian.org/pkg/linux-lts-wily","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored [end of standard support]","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-lts-xenial","source":"https://ubuntu.com/security/cve?package=linux-lts-xenial","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-lts-xenial","debian":"https://tracker.debian.org/pkg/linux-lts-xenial","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"4.4.0-13.29~14.04.1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-maguro","source":"https://ubuntu.com/security/cve?package=linux-maguro","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-maguro","debian":"https://tracker.debian.org/pkg/linux-maguro","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-mako","source":"https://ubuntu.com/security/cve?package=linux-mako","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-mako","debian":"https://tracker.debian.org/pkg/linux-mako","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-manta","source":"https://ubuntu.com/security/cve?package=linux-manta","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-manta","debian":"https://tracker.debian.org/pkg/linux-manta","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was ignored","component":null,"pocket":"security"}]},{"name":"linux-nvidia","source":"https://ubuntu.com/security/cve?package=linux-nvidia","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia","debian":"https://tracker.debian.org/pkg/linux-nvidia","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1005.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.11","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.11","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1002.2","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-nvidia-6.8","source":"https://ubuntu.com/security/cve?package=linux-nvidia-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-6.8","debian":"https://tracker.debian.org/pkg/linux-nvidia-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1008.8~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-nvidia-lowlatency","source":"https://ubuntu.com/security/cve?package=linux-nvidia-lowlatency","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-lowlatency","debian":"https://tracker.debian.org/pkg/linux-nvidia-lowlatency","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1009.9.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1013.13","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-5.15","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-5.15","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1009.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-nvidia-tegra-igx","source":"https://ubuntu.com/security/cve?package=linux-nvidia-tegra-igx","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-nvidia-tegra-igx","debian":"https://tracker.debian.org/pkg/linux-nvidia-tegra-igx","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1001.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-oem","source":"https://ubuntu.com/security/cve?package=linux-oem","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem","debian":"https://tracker.debian.org/pkg/linux-oem","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"ignored","description":"replaced by linux-hwe-5.4","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-oem-6.11","source":"https://ubuntu.com/security/cve?package=linux-oem-6.11","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.11","debian":"https://tracker.debian.org/pkg/linux-oem-6.11","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.11.0-1007.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-oem-6.14","source":"https://ubuntu.com/security/cve?package=linux-oem-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.14","debian":"https://tracker.debian.org/pkg/linux-oem-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1005.5","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-oem-6.8","source":"https://ubuntu.com/security/cve?package=linux-oem-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oem-6.8","debian":"https://tracker.debian.org/pkg/linux-oem-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1003.3","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-oracle","source":"https://ubuntu.com/security/cve?package=linux-oracle","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle","debian":"https://tracker.debian.org/pkg/linux-oracle","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.15.0-1008.10~16.04.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.15.0-1008.10","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.10","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1010.10","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1006.6","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.15","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.15","debian":"https://tracker.debian.org/pkg/linux-oracle-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1007.9~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-oracle-5.4","source":"https://ubuntu.com/security/cve?package=linux-oracle-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-5.4","debian":"https://tracker.debian.org/pkg/linux-oracle-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1021.21~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.14","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.14","debian":"https://tracker.debian.org/pkg/linux-oracle-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1007.7~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-oracle-6.8","source":"https://ubuntu.com/security/cve?package=linux-oracle-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-oracle-6.8","debian":"https://tracker.debian.org/pkg/linux-oracle-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-1006.6~22.04.3","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-qcm-msm","source":"https://ubuntu.com/security/cve?package=linux-qcm-msm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-qcm-msm","debian":"https://tracker.debian.org/pkg/linux-qcm-msm","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-raspi","source":"https://ubuntu.com/security/cve?package=linux-raspi","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi","debian":"https://tracker.debian.org/pkg/linux-raspi","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1007.7","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.13.0-1008.9","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.5.0-1005.7","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1004.4","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-raspi-5.4","source":"https://ubuntu.com/security/cve?package=linux-raspi-5.4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi-5.4","debian":"https://tracker.debian.org/pkg/linux-raspi-5.4","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"5.4.0-1013.13~18.04.1","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-raspi-realtime","source":"https://ubuntu.com/security/cve?package=linux-raspi-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi-realtime","debian":"https://tracker.debian.org/pkg/linux-raspi-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.7.0-2001.1","component":null,"pocket":"realtime"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-raspi2","source":"https://ubuntu.com/security/cve?package=linux-raspi2","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-raspi2","debian":"https://tracker.debian.org/pkg/linux-raspi2","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.10.0-1004.6","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.2.0-1013.19","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1009.10","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.8.0-1013.15","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.13.0-1005.5","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-realtime","source":"https://ubuntu.com/security/cve?package=linux-realtime","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-realtime","debian":"https://tracker.debian.org/pkg/linux-realtime","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1006.6","component":null,"pocket":"realtime"},{"release_codename":"noble","status":"not-affected","description":"6.8.0-1008.19","component":null,"pocket":"realtime"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-1001.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.14","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.14","debian":"https://tracker.debian.org/pkg/linux-realtime-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-1003.3~24.04.3","component":null,"pocket":"realtime"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-realtime-6.8","source":"https://ubuntu.com/security/cve?package=linux-realtime-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-realtime-6.8","debian":"https://tracker.debian.org/pkg/linux-realtime-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.1-1004.4~22.04.1","component":null,"pocket":"realtime"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-riscv","source":"https://ubuntu.com/security/cve?package=linux-riscv","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv","debian":"https://tracker.debian.org/pkg/linux-riscv","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"ignored","description":"end of kernel support","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"replaced by linux-riscv-6.14","component":null,"pocket":"security"},{"release_codename":"plucky","status":"not-affected","description":"6.11.0-8.8.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"end of standard support","component":null,"pocket":"security"}]},{"name":"linux-riscv-5.15","source":"https://ubuntu.com/security/cve?package=linux-riscv-5.15","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv-5.15","debian":"https://tracker.debian.org/pkg/linux-riscv-5.15","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.15.0-1015.17~20.04.1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.14","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.14","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.14","debian":"https://tracker.debian.org/pkg/linux-riscv-6.14","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"6.14.0-22.22.1~24.04.1","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-riscv-6.8","source":"https://ubuntu.com/security/cve?package=linux-riscv-6.8","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-riscv-6.8","debian":"https://tracker.debian.org/pkg/linux-riscv-6.8","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"6.8.0-38.38.1~22.04.1","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]},{"name":"linux-snapdragon","source":"https://ubuntu.com/security/cve?package=linux-snapdragon","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-snapdragon","debian":"https://tracker.debian.org/pkg/linux-snapdragon","statuses":[{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"4.4.0-1050.54","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"4.4.0-1012.12","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"4.4.0-1029.32","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.4.0-1077.82","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-ti-omap4","source":"https://ubuntu.com/security/cve?package=linux-ti-omap4","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-ti-omap4","debian":"https://tracker.debian.org/pkg/linux-ti-omap4","statuses":[{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"}]},{"name":"linux-xilinx-zynqmp","source":"https://ubuntu.com/security/cve?package=linux-xilinx-zynqmp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=linux-xilinx-zynqmp","debian":"https://tracker.debian.org/pkg/linux-xilinx-zynqmp","statuses":[{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"5.4.0-1020.24","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.15.0-1022.26","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"plucky","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.18~rc1","component":null,"pocket":"security"}]}],"notices_ids":["USN-3422-2","USN-3422-1"],"notices":[{"id":"USN-3422-2","title":"Linux kernel (Trusty HWE) vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-09-18T23:25:24.577462","description":"USN-3422-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04\nLTS. This update provides the corresponding updates for the Linux\nHardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu\n12.04 LTS.\n\nIt was discovered that a buffer overflow existed in the Bluetooth stack of\nthe Linux kernel when handling L2CAP configuration responses. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-1000251)\n\nIt was discovered that the asynchronous I/O (aio) subsystem of the Linux\nkernel did not properly set permissions on aio memory mappings in some\nsituations. An attacker could use this to more easily exploit other\nvulnerabilities. (CVE-2016-10044)\n\nBaozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3\nIP Encapsulation implementation in the Linux kernel. A local attacker could\nuse this to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2016-10200)\n\nAndreas Gruenbacher and Jan Kara discovered that the filesystem\nimplementation in the Linux kernel did not clear the setgid bit during a\nsetxattr call. A local attacker could use this to possibly elevate group\nprivileges. (CVE-2016-7097)\n\nSergej Schumilo, Ralf Spenneberg, and Hendrik Schwartke discovered that the\nkey management subsystem in the Linux kernel did not properly allocate\nmemory in some situations. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2016-8650)\n\nVlad Tsyrklevich discovered an integer overflow vulnerability in the VFIO\nPCI driver for the Linux kernel. A local attacker with access to a vfio PCI\ndevice file could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2016-9083, CVE-2016-9084)\n\nIt was discovered that an information leak existed in __get_user_asm_ex()\nin the Linux kernel. A local attacker could use this to expose sensitive\ninformation. (CVE-2016-9178)\n\nCAI Qian discovered that the sysctl implementation in the Linux kernel did\nnot properly perform reference counting in some situations. An unprivileged\nattacker could use this to cause a denial of service (system hang).\n(CVE-2016-9191)\n\nIt was discovered that the keyring implementation in the Linux kernel in\nsome situations did not prevent special internal keyrings from being joined\nby userspace keyrings. A privileged local attacker could use this to bypass\nmodule verification. (CVE-2016-9604)\n\nIt was discovered that an integer overflow existed in the trace subsystem\nof the Linux kernel. A local privileged attacker could use this to cause a\ndenial of service (system crash). (CVE-2016-9754)\n\nAndrey Konovalov discovered that the IPv4 implementation in the Linux\nkernel did not properly handle invalid IP options in some situations. An\nattacker could use this to cause a denial of service or possibly execute\narbitrary code. (CVE-2017-5970)\n\nDmitry Vyukov discovered that the Linux kernel did not properly handle TCP\npackets with the URG flag. A remote attacker could use this to cause a\ndenial of service. (CVE-2017-6214)\n\nIt was discovered that a race condition existed in the AF_PACKET handling\ncode in the Linux kernel. A local attacker could use this to cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2017-6346)\n\nIt was discovered that the keyring implementation in the Linux kernel did\nnot properly restrict searches for dead keys. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-6951)\n\nDmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linux\nkernel contained a stack-based buffer overflow. A local attacker with\naccess to an sg device could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-7187)\n\nEric Biggers discovered a memory leak in the keyring implementation in the\nLinux kernel. A local attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-7472)\n\nIt was discovered that a buffer overflow existed in the Broadcom FullMAC\nWLAN driver in the Linux kernel. A local attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2017-7541)\n","is_hidden":false,"release_packages":{"precise":[{"name":"linux-lts-trusty","version":"3.13.0-132.181~precise1","description":"Linux hardware enablement kernel from Trusty for Precise ESM","is_source":true},{"name":"linux-image-generic-lpae-lts-trusty","version":"3.13.0.132.122","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-132.181~precise1"},{"name":"linux-image-3.13.0-132-generic","version":"3.13.0-132.181~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-132.181~precise1"},{"name":"linux-image-generic-lts-trusty","version":"3.13.0.132.122","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-132.181~precise1"},{"name":"linux-image-3.13.0-132-generic-lpae","version":"3.13.0-132.181~precise1","is_source":false,"source_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty","version_link":"https://launchpad.net/ubuntu/+source/linux-lts-trusty/3.13.0-132.181~precise1"}]},"type":"USN","cves_ids":["CVE-2016-10044","CVE-2016-10200","CVE-2016-7097","CVE-2016-8650","CVE-2016-9083","CVE-2016-9084","CVE-2016-9178","CVE-2016-9191","CVE-2016-9604","CVE-2016-9754","CVE-2017-1000251","CVE-2017-5970","CVE-2017-6214","CVE-2017-6346","CVE-2017-6951","CVE-2017-7187","CVE-2017-7472","CVE-2017-7541"]},{"id":"USN-3422-1","title":"Linux kernel vulnerabilities","summary":"Several security issues were fixed in the Linux kernel.\n","instructions":"After a standard system update you need to reboot your computer to make\nall the necessary changes.\n\nATTENTION: Due to an unavoidable ABI change the kernel updates have\nbeen given a new version number, which requires you to recompile and\nreinstall all third party kernel modules you might have installed.\nUnless you manually uninstalled the standard kernel metapackages\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,\nlinux-powerpc), a standard system upgrade will automatically perform\nthis as well.\n","references":[],"published":"2017-09-18T20:29:06.024960","description":"It was discovered that a buffer overflow existed in the Bluetooth stack of\nthe Linux kernel when handling L2CAP configuration responses. A physically\nproximate attacker could use this to cause a denial of service (system\ncrash). (CVE-2017-1000251)\n\nIt was discovered that the asynchronous I/O (aio) subsystem of the Linux\nkernel did not properly set permissions on aio memory mappings in some\nsituations. An attacker could use this to more easily exploit other\nvulnerabilities. (CVE-2016-10044)\n\nBaozeng Ding and Andrey Konovalov discovered a race condition in the L2TPv3\nIP Encapsulation implementation in the Linux kernel. A local attacker could\nuse this to cause a denial of service (system crash) or possibly execute\narbitrary code. (CVE-2016-10200)\n\nAndreas Gruenbacher and Jan Kara discovered that the filesystem\nimplementation in the Linux kernel did not clear the setgid bit during a\nsetxattr call. A local attacker could use this to possibly elevate group\nprivileges. (CVE-2016-7097)\n\nSergej Schumilo, Ralf Spenneberg, and Hendrik Schwartke discovered that the\nkey management subsystem in the Linux kernel did not properly allocate\nmemory in some situations. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2016-8650)\n\nVlad Tsyrklevich discovered an integer overflow vulnerability in the VFIO\nPCI driver for the Linux kernel. A local attacker with access to a vfio PCI\ndevice file could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2016-9083, CVE-2016-9084)\n\nIt was discovered that an information leak existed in __get_user_asm_ex()\nin the Linux kernel. A local attacker could use this to expose sensitive\ninformation. (CVE-2016-9178)\n\nCAI Qian discovered that the sysctl implementation in the Linux kernel did\nnot properly perform reference counting in some situations. An unprivileged\nattacker could use this to cause a denial of service (system hang).\n(CVE-2016-9191)\n\nIt was discovered that the keyring implementation in the Linux kernel in\nsome situations did not prevent special internal keyrings from being joined\nby userspace keyrings. A privileged local attacker could use this to bypass\nmodule verification. (CVE-2016-9604)\n\nIt was discovered that an integer overflow existed in the trace subsystem\nof the Linux kernel. A local privileged attacker could use this to cause a\ndenial of service (system crash). (CVE-2016-9754)\n\nAndrey Konovalov discovered that the IPv4 implementation in the Linux\nkernel did not properly handle invalid IP options in some situations. An\nattacker could use this to cause a denial of service or possibly execute\narbitrary code. (CVE-2017-5970)\n\nDmitry Vyukov discovered that the Linux kernel did not properly handle TCP\npackets with the URG flag. A remote attacker could use this to cause a\ndenial of service. (CVE-2017-6214)\n\nIt was discovered that a race condition existed in the AF_PACKET handling\ncode in the Linux kernel. A local attacker could use this to cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2017-6346)\n\nIt was discovered that the keyring implementation in the Linux kernel did\nnot properly restrict searches for dead keys. A local attacker could use\nthis to cause a denial of service (system crash). (CVE-2017-6951)\n\nDmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linux\nkernel contained a stack-based buffer overflow. A local attacker with\naccess to an sg device could use this to cause a denial of service (system\ncrash) or possibly execute arbitrary code. (CVE-2017-7187)\n\nEric Biggers discovered a memory leak in the keyring implementation in the\nLinux kernel. A local attacker could use this to cause a denial of service\n(memory consumption). (CVE-2017-7472)\n\nIt was discovered that a buffer overflow existed in the Broadcom FullMAC\nWLAN driver in the Linux kernel. A local attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2017-7541)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"linux","version":"3.13.0-132.181","description":"Linux kernel","is_source":true},{"name":"linux-image-3.13.0-132-generic","version":"3.13.0-132.181","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-132.181","pocket":"security"},{"name":"linux-image-3.13.0-132-generic-lpae","version":"3.13.0-132.181","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-132.181","pocket":"security"},{"name":"linux-image-3.13.0-132-lowlatency","version":"3.13.0-132.181","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-132.181","pocket":"security"},{"name":"linux-image-3.13.0-132-powerpc-e500","version":"3.13.0-132.181","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-132.181","pocket":"security"},{"name":"linux-image-3.13.0-132-powerpc-e500mc","version":"3.13.0-132.181","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-132.181","pocket":"security"},{"name":"linux-image-3.13.0-132-powerpc-smp","version":"3.13.0-132.181","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-132.181","pocket":"security"},{"name":"linux-image-3.13.0-132-powerpc64-emb","version":"3.13.0-132.181","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-132.181","pocket":"security"},{"name":"linux-image-3.13.0-132-powerpc64-smp","version":"3.13.0-132.181","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-132.181","pocket":"security"},{"name":"linux-image-extra-3.13.0-132-generic","version":"3.13.0-132.181","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/linux","version_link":"https://launchpad.net/ubuntu/+source/linux/3.13.0-132.181","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2016-10044","CVE-2016-10200","CVE-2016-7097","CVE-2016-8650","CVE-2016-9083","CVE-2016-9084","CVE-2016-9178","CVE-2016-9191","CVE-2016-9604","CVE-2016-9754","CVE-2017-1000251","CVE-2017-5970","CVE-2017-6214","CVE-2017-6346","CVE-2017-6951","CVE-2017-7187","CVE-2017-7472","CVE-2017-7541"]}]},{"id":"CVE-2017-5857","published":"2017-03-16T00:00:00","updated_at":"2025-08-25T22:35:16.612958+00:00","description":"\nMemory leak in the virgl_cmd_resource_unref function in\nhw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest\nOS users to cause a denial of service (host memory consumption) via a large\nnumber of VIRTIO_GPU_CMD_RESOURCE_UNREF commands sent without detaching the\nbacking storage beforehand.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://lists.nongnu.org/archive/html/qemu-devel/2017-01/msg04615.html","http://www.openwall.com/lists/oss-security/2017/02/01/21c","https://ubuntu.com/security/notices/USN-3261-1","https://www.cve.org/CVERecord?id=CVE-2017-5857"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1418382","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853996"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu-project.org/?p=qemu.git;a=commit;h=5e8e3c4c75c199aa1017db816fca02be2a9f8798"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.11","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:2.6.1+dfsg-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"precise","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3261-1"],"notices":[{"id":"USN-3261-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2017-04-20T18:33:13.848442","description":"Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU\ndevice. An attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)\n\nLi Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-10155)\n\nLi Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. This issue only\naffected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7907)\n\nIt was discovered that QEMU incorrectly handled the JAZZ RC4030 device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8667)\n\nIt was discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8669)\n\nIt was discovered that QEMU incorrectly handled the shared rings when used\nwith Xen. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. (CVE-2016-9381)\n\nJann Horn discovered that QEMU incorrectly handled VirtFS directory\nsharing. A privileged attacker inside the guest could use this issue to\naccess files on the host file system outside of the shared directory and\npossibly escalate their privileges. In the default installation, when QEMU\nis used with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. (CVE-2016-9602)\n\nGerd Hoffmann discovered that QEMU incorrectly handled the Cirrus VGA\ndevice when being used with a VNC connection. A privileged attacker inside\nthe guest could use this issue to cause QEMU to crash, resulting in a\ndenial of service, or possibly execute arbitrary code on the host. In the\ndefault installation, when QEMU is used with libvirt, attackers would be\nisolated by the libvirt AppArmor profile. (CVE-2016-9603)\n\nIt was discovered that QEMU incorrectly handled the ColdFire Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2016-9776)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to leak\ncontents of host memory. This issue only affected Ubuntu 16.04 LTS and\nUbuntu 16.10. (CVE-2016-9845, CVE-2016-9908)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9846, CVE-2016-9912, CVE-2017-5552,\nCVE-2017-5578, CVE-2017-5857)\n\nLi Qiang discovered that QEMU incorrectly handled the USB redirector. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9907)\n\nLi Qiang discovered that QEMU incorrectly handled USB EHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2016-9911)\n\nLi Qiang discovered that QEMU incorrectly handled VirtFS directory sharing.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2016-9913, CVE-2016-9914,\nCVE-2016-9915, CVE-2016-9916)\n\nQinghao Tang, Li Qiang, and Jiangxin discovered that QEMU incorrectly\nhandled the Cirrus VGA device. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2016-9921, CVE-2016-9922)\n\nWjjzhang and Li Qiang discovered that QEMU incorrectly handled the Cirrus\nVGA device. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. In the default installation, when QEMU is used\nwith libvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2615)\n\nIt was discovered that QEMU incorrectly handled the Cirrus VGA device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service, or possibly execute arbitrary code\non the host. In the default installation, when QEMU is used with libvirt,\nattackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2620)\n\nIt was discovered that QEMU incorrectly handled VNC connections. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2017-2633)\n\nLi Qiang discovered that QEMU incorrectly handled the ac97 audio device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5525)\n\nLi Qiang discovered that QEMU incorrectly handled the es1370 audio device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5526)\n\nLi Qiang discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5579)\n\nJiang Xin discovered that QEMU incorrectly handled SDHCI device emulation.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode on the host. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-5667)\n\nLi Qiang discovered that QEMU incorrectly handled the MegaRAID SAS device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5856)\n\nLi Qiang discovered that QEMU incorrectly handled the CCID Card device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5898)\n\nLi Qiang discovered that QEMU incorrectly handled USB xHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2017-5973)\n\nJiang Xin and Wjjzhang discovered that QEMU incorrectly handled SDHCI\ndevice emulation. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2017-5987)\n\nLi Qiang discovered that QEMU incorrectly handled USB OHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to hang, resulting in a denial of service. (CVE-2017-6505)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"}],"yakkety":[{"name":"qemu","version":"1:2.6.1+dfsg-0ubuntu5.4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-aarch64","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-arm","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-mips","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-misc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-ppc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-s390x","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-sparc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-x86","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"}]},"type":"USN","cves_ids":["CVE-2016-10028","CVE-2016-10029","CVE-2016-10155","CVE-2016-7907","CVE-2016-8667","CVE-2016-8669","CVE-2016-9381","CVE-2016-9602","CVE-2016-9603","CVE-2016-9776","CVE-2016-9845","CVE-2016-9846","CVE-2016-9907","CVE-2016-9908","CVE-2016-9911","CVE-2016-9912","CVE-2016-9913","CVE-2016-9914","CVE-2016-9915","CVE-2016-9916","CVE-2016-9921","CVE-2016-9922","CVE-2017-2615","CVE-2017-2620","CVE-2017-2633","CVE-2017-5525","CVE-2017-5526","CVE-2017-5552","CVE-2017-5578","CVE-2017-5579","CVE-2017-5667","CVE-2017-5856","CVE-2017-5857","CVE-2017-5898","CVE-2017-5973","CVE-2017-5987","CVE-2017-6505"]}]},{"id":"CVE-2017-5856","published":"2017-03-16T00:00:00","updated_at":"2025-08-25T22:35:16.612958+00:00","description":"\nMemory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in\nQEMU (aka Quick Emulator) allows local guest OS privileged users to cause a\ndenial of service (host memory consumption) via MegaRAID Firmware Interface\n(MFI) commands with the sglist size set to a value over 2 Gb.","ubuntu_description":"","notes":[],"codename":null,"priority":"low","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/02/01/19","https://ubuntu.com/security/notices/USN-3261-1","https://www.cve.org/CVERecord?id=CVE-2017-5856"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1418342","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853996"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu.org/?p=qemu.git;a=commit;h=765a707000e838c30b18d712fe6cb3dd8e0435f3"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"groovy","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"artful","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.33","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.11","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:2.6.1+dfsg-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3261-1"],"notices":[{"id":"USN-3261-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2017-04-20T18:33:13.848442","description":"Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU\ndevice. An attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)\n\nLi Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-10155)\n\nLi Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. This issue only\naffected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7907)\n\nIt was discovered that QEMU incorrectly handled the JAZZ RC4030 device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8667)\n\nIt was discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8669)\n\nIt was discovered that QEMU incorrectly handled the shared rings when used\nwith Xen. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. (CVE-2016-9381)\n\nJann Horn discovered that QEMU incorrectly handled VirtFS directory\nsharing. A privileged attacker inside the guest could use this issue to\naccess files on the host file system outside of the shared directory and\npossibly escalate their privileges. In the default installation, when QEMU\nis used with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. (CVE-2016-9602)\n\nGerd Hoffmann discovered that QEMU incorrectly handled the Cirrus VGA\ndevice when being used with a VNC connection. A privileged attacker inside\nthe guest could use this issue to cause QEMU to crash, resulting in a\ndenial of service, or possibly execute arbitrary code on the host. In the\ndefault installation, when QEMU is used with libvirt, attackers would be\nisolated by the libvirt AppArmor profile. (CVE-2016-9603)\n\nIt was discovered that QEMU incorrectly handled the ColdFire Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2016-9776)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to leak\ncontents of host memory. This issue only affected Ubuntu 16.04 LTS and\nUbuntu 16.10. (CVE-2016-9845, CVE-2016-9908)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9846, CVE-2016-9912, CVE-2017-5552,\nCVE-2017-5578, CVE-2017-5857)\n\nLi Qiang discovered that QEMU incorrectly handled the USB redirector. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9907)\n\nLi Qiang discovered that QEMU incorrectly handled USB EHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2016-9911)\n\nLi Qiang discovered that QEMU incorrectly handled VirtFS directory sharing.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2016-9913, CVE-2016-9914,\nCVE-2016-9915, CVE-2016-9916)\n\nQinghao Tang, Li Qiang, and Jiangxin discovered that QEMU incorrectly\nhandled the Cirrus VGA device. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2016-9921, CVE-2016-9922)\n\nWjjzhang and Li Qiang discovered that QEMU incorrectly handled the Cirrus\nVGA device. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. In the default installation, when QEMU is used\nwith libvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2615)\n\nIt was discovered that QEMU incorrectly handled the Cirrus VGA device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service, or possibly execute arbitrary code\non the host. In the default installation, when QEMU is used with libvirt,\nattackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2620)\n\nIt was discovered that QEMU incorrectly handled VNC connections. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2017-2633)\n\nLi Qiang discovered that QEMU incorrectly handled the ac97 audio device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5525)\n\nLi Qiang discovered that QEMU incorrectly handled the es1370 audio device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5526)\n\nLi Qiang discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5579)\n\nJiang Xin discovered that QEMU incorrectly handled SDHCI device emulation.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode on the host. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-5667)\n\nLi Qiang discovered that QEMU incorrectly handled the MegaRAID SAS device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5856)\n\nLi Qiang discovered that QEMU incorrectly handled the CCID Card device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5898)\n\nLi Qiang discovered that QEMU incorrectly handled USB xHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2017-5973)\n\nJiang Xin and Wjjzhang discovered that QEMU incorrectly handled SDHCI\ndevice emulation. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2017-5987)\n\nLi Qiang discovered that QEMU incorrectly handled USB OHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to hang, resulting in a denial of service. (CVE-2017-6505)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"}],"yakkety":[{"name":"qemu","version":"1:2.6.1+dfsg-0ubuntu5.4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-aarch64","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-arm","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-mips","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-misc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-ppc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-s390x","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-sparc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-x86","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"}]},"type":"USN","cves_ids":["CVE-2016-10028","CVE-2016-10029","CVE-2016-10155","CVE-2016-7907","CVE-2016-8667","CVE-2016-8669","CVE-2016-9381","CVE-2016-9602","CVE-2016-9603","CVE-2016-9776","CVE-2016-9845","CVE-2016-9846","CVE-2016-9907","CVE-2016-9908","CVE-2016-9911","CVE-2016-9912","CVE-2016-9913","CVE-2016-9914","CVE-2016-9915","CVE-2016-9916","CVE-2016-9921","CVE-2016-9922","CVE-2017-2615","CVE-2017-2620","CVE-2017-2633","CVE-2017-5525","CVE-2017-5526","CVE-2017-5552","CVE-2017-5578","CVE-2017-5579","CVE-2017-5667","CVE-2017-5856","CVE-2017-5857","CVE-2017-5898","CVE-2017-5973","CVE-2017-5987","CVE-2017-6505"]}]},{"id":"CVE-2017-5667","published":"2017-03-16T00:00:00","updated_at":"2025-08-25T22:34:58.789019+00:00","description":"\nThe sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka\nQuick Emulator) allows local guest OS privileged users to cause a denial of\nservice (out-of-bounds heap access and crash) or execute arbitrary code on\nthe QEMU host via vectors involving the data transfer length.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://lists.gnu.org/archive/html/qemu-devel/2017-01/msg06191.html","http://www.openwall.com/lists/oss-security/2017/01/30/2","https://ubuntu.com/security/notices/USN-3261-1","https://www.cve.org/CVERecord?id=CVE-2017-5667"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1417559","https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853996"],"patches":{"qemu-kvm":[],"qemu":["upstream: http://git.qemu-project.org/?p=qemu.git;a=commit;h=42922105beb14c2fc58185ea022b9f72fb5465e9"]},"tags":{},"packages":[{"name":"qemu","source":"https://ubuntu.com/security/cve?package=qemu","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu","debian":"https://tracker.debian.org/pkg/qemu","statuses":[{"release_codename":"artful","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"2.0.0+dfsg-2ubuntu1.33","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:2.5+dfsg-5ubuntu10.11","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:2.6.1+dfsg-0ubuntu5.4","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1:2.8+dfsg-3ubuntu2","component":null,"pocket":"security"}]},{"name":"qemu-kvm","source":"https://ubuntu.com/security/cve?package=qemu-kvm","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=qemu-kvm","debian":"https://tracker.debian.org/pkg/qemu-kvm","statuses":[{"release_codename":"hirsute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"artful","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"disco","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"eoan","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"groovy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"zesty","status":"DNE","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-3261-1"],"notices":[{"id":"USN-3261-1","title":"QEMU vulnerabilities","summary":"Several security issues were fixed in QEMU.\n","instructions":"After a standard system update you need to restart all QEMU virtual\nmachines to make all the necessary changes.\n","references":[],"published":"2017-04-20T18:33:13.848442","description":"Zhenhao Hong discovered that QEMU incorrectly handled the Virtio GPU\ndevice. An attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. This issue only affected Ubuntu\n16.04 LTS and Ubuntu 16.10. (CVE-2016-10028, CVE-2016-10029)\n\nLi Qiang discovered that QEMU incorrectly handled the 6300esb watchdog. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-10155)\n\nLi Qiang discovered that QEMU incorrectly handled the i.MX Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. This issue only\naffected Ubuntu 16.04 LTS and Ubuntu 16.10. (CVE-2016-7907)\n\nIt was discovered that QEMU incorrectly handled the JAZZ RC4030 device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8667)\n\nIt was discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2016-8669)\n\nIt was discovered that QEMU incorrectly handled the shared rings when used\nwith Xen. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. (CVE-2016-9381)\n\nJann Horn discovered that QEMU incorrectly handled VirtFS directory\nsharing. A privileged attacker inside the guest could use this issue to\naccess files on the host file system outside of the shared directory and\npossibly escalate their privileges. In the default installation, when QEMU\nis used with libvirt, attackers would be isolated by the libvirt AppArmor\nprofile. (CVE-2016-9602)\n\nGerd Hoffmann discovered that QEMU incorrectly handled the Cirrus VGA\ndevice when being used with a VNC connection. A privileged attacker inside\nthe guest could use this issue to cause QEMU to crash, resulting in a\ndenial of service, or possibly execute arbitrary code on the host. In the\ndefault installation, when QEMU is used with libvirt, attackers would be\nisolated by the libvirt AppArmor profile. (CVE-2016-9603)\n\nIt was discovered that QEMU incorrectly handled the ColdFire Fast Ethernet\nController. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2016-9776)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to leak\ncontents of host memory. This issue only affected Ubuntu 16.04 LTS and\nUbuntu 16.10. (CVE-2016-9845, CVE-2016-9908)\n\nLi Qiang discovered that QEMU incorrectly handled the Virtio GPU device. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9846, CVE-2016-9912, CVE-2017-5552,\nCVE-2017-5578, CVE-2017-5857)\n\nLi Qiang discovered that QEMU incorrectly handled the USB redirector. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. This issue only affected Ubuntu 16.04 LTS\nand Ubuntu 16.10. (CVE-2016-9907)\n\nLi Qiang discovered that QEMU incorrectly handled USB EHCI emulation. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2016-9911)\n\nLi Qiang discovered that QEMU incorrectly handled VirtFS directory sharing.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2016-9913, CVE-2016-9914,\nCVE-2016-9915, CVE-2016-9916)\n\nQinghao Tang, Li Qiang, and Jiangxin discovered that QEMU incorrectly\nhandled the Cirrus VGA device. A privileged attacker inside the guest could\nuse this issue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2016-9921, CVE-2016-9922)\n\nWjjzhang and Li Qiang discovered that QEMU incorrectly handled the Cirrus\nVGA device. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service, or possibly execute\narbitrary code on the host. In the default installation, when QEMU is used\nwith libvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2615)\n\nIt was discovered that QEMU incorrectly handled the Cirrus VGA device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service, or possibly execute arbitrary code\non the host. In the default installation, when QEMU is used with libvirt,\nattackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-2620)\n\nIt was discovered that QEMU incorrectly handled VNC connections. An\nattacker inside the guest could use this issue to cause QEMU to crash,\nresulting in a denial of service. (CVE-2017-2633)\n\nLi Qiang discovered that QEMU incorrectly handled the ac97 audio device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5525)\n\nLi Qiang discovered that QEMU incorrectly handled the es1370 audio device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5526)\n\nLi Qiang discovered that QEMU incorrectly handled the 16550A UART device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5579)\n\nJiang Xin discovered that QEMU incorrectly handled SDHCI device emulation.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service, or possibly execute arbitrary\ncode on the host. In the default installation, when QEMU is used with\nlibvirt, attackers would be isolated by the libvirt AppArmor profile.\n(CVE-2017-5667)\n\nLi Qiang discovered that QEMU incorrectly handled the MegaRAID SAS device.\nA privileged attacker inside the guest could use this issue to cause QEMU\nto crash, resulting in a denial of service. (CVE-2017-5856)\n\nLi Qiang discovered that QEMU incorrectly handled the CCID Card device. A\nprivileged attacker inside the guest could use this issue to cause QEMU to\ncrash, resulting in a denial of service. (CVE-2017-5898)\n\nLi Qiang discovered that QEMU incorrectly handled USB xHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to crash, resulting in a denial of service. (CVE-2017-5973)\n\nJiang Xin and Wjjzhang discovered that QEMU incorrectly handled SDHCI\ndevice emulation. A privileged attacker inside the guest could use this\nissue to cause QEMU to crash, resulting in a denial of service.\n(CVE-2017-5987)\n\nLi Qiang discovered that QEMU incorrectly handled USB OHCI controller\nemulation. A privileged attacker inside the guest could use this issue to\ncause QEMU to hang, resulting in a denial of service. (CVE-2017-6505)\n","is_hidden":false,"release_packages":{"trusty":[{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-guest-agent","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-keymaps","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-kvm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-aarch64","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-arm","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-common","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-mips","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-misc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-ppc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-sparc","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-system-x86","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-user-static","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"},{"name":"qemu-utils","version":"2.0.0+dfsg-2ubuntu1.33","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/2.0.0+dfsg-2ubuntu1.33","pocket":"security"}],"xenial":[{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-block-extra","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-guest-agent","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-kvm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-aarch64","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-arm","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-common","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-mips","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-misc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-ppc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-s390x","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-sparc","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-system-x86","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-binfmt","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-user-static","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"},{"name":"qemu-utils","version":"1:2.5+dfsg-5ubuntu10.11","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.5+dfsg-5ubuntu10.11","pocket":"security"}],"yakkety":[{"name":"qemu","version":"1:2.6.1+dfsg-0ubuntu5.4","description":"Machine emulator and virtualizer","is_source":true},{"name":"qemu-system","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-aarch64","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-arm","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-mips","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-misc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-ppc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-s390x","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-sparc","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"},{"name":"qemu-system-x86","version":"1:2.6.1+dfsg-0ubuntu5.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/qemu","version_link":"https://launchpad.net/ubuntu/+source/qemu/1:2.6.1+dfsg-0ubuntu5.4"}]},"type":"USN","cves_ids":["CVE-2016-10028","CVE-2016-10029","CVE-2016-10155","CVE-2016-7907","CVE-2016-8667","CVE-2016-8669","CVE-2016-9381","CVE-2016-9602","CVE-2016-9603","CVE-2016-9776","CVE-2016-9845","CVE-2016-9846","CVE-2016-9907","CVE-2016-9908","CVE-2016-9911","CVE-2016-9912","CVE-2016-9913","CVE-2016-9914","CVE-2016-9915","CVE-2016-9916","CVE-2016-9921","CVE-2016-9922","CVE-2017-2615","CVE-2017-2620","CVE-2017-2633","CVE-2017-5525","CVE-2017-5526","CVE-2017-5552","CVE-2017-5578","CVE-2017-5579","CVE-2017-5667","CVE-2017-5856","CVE-2017-5857","CVE-2017-5898","CVE-2017-5973","CVE-2017-5987","CVE-2017-6505"]}]},{"id":"CVE-2017-5937","published":"2017-03-15T19:59:00","updated_at":"2025-08-25T22:35:27.038421+00:00","description":"\nThe util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d\nproject (aka virglrenderer) 0.6.0 and earlier allows local guest OS users\nto cause a denial of service (NULL pointer dereference) via a crafted\nVIRGL_CCMD_CLEAR command.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://cgit.freedesktop.org/virglrenderer/commit/?id=48f67f60967f963b698ec8df57ec6912a43d6282","https://bugzilla.redhat.com/show_bug.cgi?id=1420246","https://www.cve.org/CVERecord?id=CVE-2017-5937"],"bugs":[""],"patches":{"virglrenderer":[]},"tags":{},"packages":[{"name":"virglrenderer","source":"https://ubuntu.com/security/cve?package=virglrenderer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=virglrenderer","debian":"https://tracker.debian.org/pkg/virglrenderer","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.6.0-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.6.0-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5849","published":"2017-03-15T19:59:00","updated_at":"2025-08-25T22:35:16.612958+00:00","description":"\ntiffttopnm in netpbm 10.47.63 does not properly use the libtiff\nTIFFRGBAImageGet function, which allows remote attackers to cause a denial\nof service (out-of-bounds read and write) via a crafted tiff image file,\nrelated to transposing width and height values.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Debian and Ubuntu use a netpbm fork which does not contain the\nissue. See here:\nhttp://bugzilla.maptools.org/show_bug.cgi?id=2654#c8"}],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["http://www.openwall.com/lists/oss-security/2017/02/02/2","https://www.cve.org/CVERecord?id=CVE-2017-5849"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=853997","http://bugzilla.maptools.org/show_bug.cgi?id=2654","http://bugzilla.maptools.org/show_bug.cgi?id=2655"],"patches":{"netpbm-free":[]},"tags":{},"packages":[{"name":"netpbm-free","source":"https://ubuntu.com/security/cve?package=netpbm-free","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=netpbm-free","debian":"https://tracker.debian.org/pkg/netpbm-free","statuses":[{"release_codename":"upstream","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"precise","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-5239","published":"2017-03-15T19:59:00","updated_at":"2025-08-25T22:05:45.761721+00:00","description":"\nThe gnuplot delegate functionality in ImageMagick before 6.9.4-0 and\nGraphicsMagick allows remote attackers to execute arbitrary commands via\nunspecified vectors.","ubuntu_description":"\nIt was discovered that GraphicsMagick incorrectly handled certain image\nfiles. An attacker could possibly use this issue to cause a denial of\nservice or other unspecified impact.","notes":[{"author":"mdeslaur","note":"This is 0077-Drop-the-PLT-Gnuplot-decoder.patch"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2016-5239"],"bugs":["https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1615926"],"patches":{"graphicsmagick":[],"imagemagick":["upstream: http://git.imagemagick.org/repos/ImageMagick/commit/70a2cf326ed32bedee144b961005c63846541a16"]},"tags":{},"packages":[{"name":"graphicsmagick","source":"https://ubuntu.com/security/cve?package=graphicsmagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=graphicsmagick","debian":"https://tracker.debian.org/pkg/graphicsmagick","statuses":[{"release_codename":"artful","status":"not-affected","description":"1.3.24-1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.3.24-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.3.24-1","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.3.18-1ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.3.24-1","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1.3.23-1ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"not-affected","description":"1.3.24-1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"1.3.24-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"}]},{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:6.8.9.9-5+deb8u2","component":null,"pocket":"security"},{"release_codename":"artful","status":"released","description":"8:6.8.9.9-7ubuntu7","component":null,"pocket":"security"},{"release_codename":"bionic","status":"released","description":"8:6.8.9.9-7ubuntu7","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"released","description":"8:6.8.9.9-7ubuntu7","component":null,"pocket":"security"},{"release_codename":"wily","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"8:6.8.9.9-7ubuntu7","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"8:6.8.9.9-7ubuntu7","component":null,"pocket":"security"},{"release_codename":"precise","status":"released","description":"8:6.6.9.7-5ubuntu3.4","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5522","published":"2017-03-15T16:59:00","updated_at":"2025-08-25T22:34:43.623689+00:00","description":"\nStack-based buffer overflow in MapServer before 6.0.6, 6.2.x before 6.2.4,\n6.4.x before 6.4.5, and 7.0.x before 7.0.4 allows remote attackers to cause\na denial of service (crash) or execute arbitrary code via vectors involving\nWFS get feature requests.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://lists.osgeo.org/pipermail/mapserver-dev/2017-January/015007.html","https://github.com/mapserver/mapserver/commit/e52a436c0e1c5e9f7ef13428dba83194a800f4df","https://www.cve.org/CVERecord?id=CVE-2017-5522"],"bugs":[""],"patches":{"mapserver":[]},"tags":{},"packages":[{"name":"mapserver","source":"https://ubuntu.com/security/cve?package=mapserver","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=mapserver","debian":"https://tracker.debian.org/pkg/mapserver","statuses":[{"release_codename":"artful","status":"not-affected","description":"7.0.4-2","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"7.0.4-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"7.0.4-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"6.4.1-2ubuntu0.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"7.0.4-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"7.0.0-9ubuntu3.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"not-affected","description":"7.0.4-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2016-7103","published":"2017-03-15T16:59:00","updated_at":"2025-08-25T22:09:43.254844+00:00","description":"\nCross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might\nallow remote attackers to inject arbitrary web script or HTML via the\ncloseText parameter of the dialog function.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://nodesecurity.io/advisories/127","https://github.com/jquery/jquery-ui/pull/1622","https://github.com/jquery/jquery-ui/pull/1632","https://github.com/jquery/api.jqueryui.com/issues/281","https://ubuntu.com/security/notices/USN-6419-1","https://www.cve.org/CVERecord?id=CVE-2016-7103"],"bugs":[""],"patches":{"jqueryui":[]},"tags":{},"packages":[{"name":"jqueryui","source":"https://ubuntu.com/security/cve?package=jqueryui","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=jqueryui","debian":"https://tracker.debian.org/pkg/jqueryui","statuses":[{"release_codename":"impish","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"hirsute","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1.10.1+dfsg-1ubuntu0.14.04.1~esm1","component":null,"pocket":"esm-infra"},{"release_codename":"xenial","status":"released","description":"1.10.1+dfsg-1ubuntu0.16.04.1~esm1","component":null,"pocket":"esm-apps"},{"release_codename":"kinetic","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"disco","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"eoan","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"groovy","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"lunar","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.12.1+dfsg-4","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"mantic","status":"not-affected","description":"1.12.1+dfsg-4","component":null,"pocket":"security"}]}],"notices_ids":["USN-6419-1"],"notices":[{"id":"USN-6419-1","title":"jQuery UI vulnerabilities","summary":"Several security issues were fixed in jQuery UI.\n","instructions":"In general, a standard system update will make all the necessary changes.\n","references":[],"published":"2023-10-05T12:36:27.583415","description":"Hong Phat Ly discovered that jQuery UI did not properly manage parameters\nfrom untrusted sources, which could lead to arbitrary web script or HTML\ncode injection. A remote attacker could possibly use this issue to perform\na cross-site scripting (XSS) attack. This issue only affected\nUbuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-7103)\n\nEsben Sparre Andreasen discovered that jQuery UI did not properly handle\nvalues from untrusted sources in the Datepicker widget. A remote attacker\ncould possibly use this issue to perform a cross-site scripting (XSS)\nattack and execute arbitrary code. This issue only affected\nUbuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.\n(CVE-2021-41182, CVE-2021-41183)\n\nIt was discovered that jQuery UI did not properly validate values from\nuntrusted sources. An attacker could possibly use this issue to cause a\ndenial of service or execute arbitrary code. This issue only affected\nUbuntu 20.04 LTS. (CVE-2021-41184)\n\nIt was discovered that the jQuery UI checkboxradio widget did not properly\ndecode certain values from HTML entities. An attacker could possibly use\nthis issue to perform a cross-site scripting (XSS) attack and cause a\ndenial of service or execute arbitrary code. This issue only affected\nUbuntu 20.04 LTS. (CVE-2022-31160)\n","is_hidden":false,"release_packages":{"bionic":[{"name":"jqueryui","version":"1.12.1+dfsg-5ubuntu0.18.04.1~esm3","description":"JavaScript UI library for dynamic web applications","is_source":true},{"name":"libjs-jquery-ui","version":"1.12.1+dfsg-5ubuntu0.18.04.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":null,"pocket":"esm-apps"},{"name":"libjs-jquery-ui-docs","version":"1.12.1+dfsg-5ubuntu0.18.04.1~esm3","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":null,"pocket":"esm-apps"},{"name":"node-jquery-ui","version":"1.12.1+dfsg-5ubuntu0.18.04.1~esm3","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":null,"pocket":"esm-apps"}],"focal":[{"name":"jqueryui","version":"1.12.1+dfsg-5ubuntu0.20.04.1","description":"JavaScript UI library for dynamic web applications","is_source":true},{"name":"libjs-jquery-ui","version":"1.12.1+dfsg-5ubuntu0.20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":"https://launchpad.net/ubuntu/+source/jqueryui/1.12.1+dfsg-5ubuntu0.20.04.1","pocket":"security"},{"name":"libjs-jquery-ui-docs","version":"1.12.1+dfsg-5ubuntu0.20.04.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":"https://launchpad.net/ubuntu/+source/jqueryui/1.12.1+dfsg-5ubuntu0.20.04.1","pocket":"security"},{"name":"node-jquery-ui","version":"1.12.1+dfsg-5ubuntu0.20.04.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":"https://launchpad.net/ubuntu/+source/jqueryui/1.12.1+dfsg-5ubuntu0.20.04.1","pocket":"security"}],"trusty":[{"name":"jqueryui","version":"1.10.1+dfsg-1ubuntu0.14.04.1~esm1","description":"JavaScript UI library for dynamic web applications","is_source":true},{"name":"libjs-jquery-ui","version":"1.10.1+dfsg-1ubuntu0.14.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":null,"pocket":"esm-infra"},{"name":"libjs-jquery-ui-docs","version":"1.10.1+dfsg-1ubuntu0.14.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":null,"pocket":"esm-infra"}],"xenial":[{"name":"jqueryui","version":"1.10.1+dfsg-1ubuntu0.16.04.1~esm1","description":"JavaScript UI library for dynamic web applications","is_source":true},{"name":"libjs-jquery-ui","version":"1.10.1+dfsg-1ubuntu0.16.04.1~esm1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":null,"pocket":"esm-apps"},{"name":"libjs-jquery-ui-docs","version":"1.10.1+dfsg-1ubuntu0.16.04.1~esm1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/jqueryui","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2021-41183","CVE-2022-31160","CVE-2021-41184","CVE-2021-41182","CVE-2016-7103"]}]},{"id":"CVE-2017-6430","published":"2017-03-15T15:59:00","updated_at":"2025-08-25T22:36:11.656966+00:00","description":"\nThe compile_tree function in ef_compiler.c in the Etterfilter utility in\nEttercap 0.8.2 and earlier allows remote attackers to cause a denial of\nservice (out-of-bounds read) via a crafted filter.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://github.com/Ettercap/ettercap/issues/782","https://www.cve.org/CVERecord?id=CVE-2017-6430"],"bugs":[""],"patches":{"ettercap":["other: https://github.com/LocutusOfBorg/ettercap/commit/626dc56686f15f2dda13c48f78c2a666cb6d8506"]},"tags":{},"packages":[{"name":"ettercap","source":"https://ubuntu.com/security/cve?package=ettercap","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=ettercap","debian":"https://tracker.debian.org/pkg/ettercap","statuses":[{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"released","description":"1:0.8.0-11ubuntu0.3","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"released","description":"1:0.8.2-2ubuntu1.16.04.1","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"released","description":"1:0.8.2-2ubuntu1.16.10.1","component":null,"pocket":"security"},{"release_codename":"zesty","status":"released","description":"1:0.8.2-4ubuntu1.17.04.1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-6429","published":"2017-03-15T15:59:00","updated_at":"2025-08-25T22:36:11.656966+00:00","description":"\nBuffer overflow in the tcpcapinfo utility in Tcpreplay before 4.2.0 Beta 1\nallows remote attackers to have unspecified impact via a pcap file with an\nover-size packet.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://github.com/appneta/tcpreplay/issues/278","https://github.com/appneta/tcpreplay/commit/d689d14dbcd768c028eab2fb378d849e543dcfe9","https://www.cve.org/CVERecord?id=CVE-2017-6429"],"bugs":[""],"patches":{"tcpreplay":["upstream: https://github.com/appneta/tcpreplay/commit/d689d14dbcd768c028eab2fb378d849e543dcfe9"]},"tags":{},"packages":[{"name":"tcpreplay","source":"https://ubuntu.com/security/cve?package=tcpreplay","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=tcpreplay","debian":"https://tracker.debian.org/pkg/tcpreplay","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"4.2.6-1","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"4.2.6-1","component":null,"pocket":"security"},{"release_codename":"precise","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"4.2.0","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"trusty was not-affected [code not present]","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2017-5580","published":"2017-03-15T15:59:00","updated_at":"2025-08-25T22:34:48.626806+00:00","description":"\nThe parse_instruction function in gallium/auxiliary/tgsi/tgsi_text.c in\nvirglrenderer before 0.6.0 allows local guest OS users to cause a denial of\nservice (out-of-bounds array access and process crash) via a crafted\ntexture instruction.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://lists.freedesktop.org/archives/virglrenderer-devel/2017-January/000105.html","http://openwall.com/lists/oss-security/2017/01/25/5","https://www.cve.org/CVERecord?id=CVE-2017-5580"],"bugs":["https://bugzilla.redhat.com/show_bug.cgi?id=1415986","http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=852604"],"patches":{"virglrenderer":[]},"tags":{},"packages":[{"name":"virglrenderer","source":"https://ubuntu.com/security/cve?package=virglrenderer","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=virglrenderer","debian":"https://tracker.debian.org/pkg/virglrenderer","statuses":[{"release_codename":"artful","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"0.6.0-2","component":null,"pocket":"security"},{"release_codename":"cosmic","status":"not-affected","description":"0.6.0-2","component":null,"pocket":"security"},{"release_codename":"precise","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"trusty","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.6.0-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"yakkety","status":"ignored","description":"end of life","component":null,"pocket":"security"},{"release_codename":"zesty","status":"ignored","description":"end of life","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":57800,"limit":20,"total_results":79316}