{"cves":[{"id":"CVE-2026-16353","published":"2026-07-21T13:17:00","updated_at":"2026-08-06T19:57:08.220653+00:00","description":"\nInvalid pointer in the DOM: Bindings (WebIDL) component. This vulnerability\nwas fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR 140.13,\nThunderbird 153, and Thunderbird 140.13.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-16353","https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16353","https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16353"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-16352","published":"2026-07-21T13:17:00","updated_at":"2026-08-06T19:57:12.513450+00:00","description":"\nSandbox escape due to use-after-free in the Disability Access APIs\ncomponent. This vulnerability was fixed in Firefox 153, Firefox ESR 115.38,\nFirefox ESR 140.13, Thunderbird 153, and Thunderbird 140.13.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-16352","https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16352","https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16352"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-16351","published":"2026-07-21T13:17:00","updated_at":"2026-08-06T19:57:17.262186+00:00","description":"\nSandbox escape due to use-after-free in the DOM: Navigation component. This\nvulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR\n140.13, Thunderbird 153, and Thunderbird 140.13.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-16351","https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16351","https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16351"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-16350","published":"2026-07-21T13:17:00","updated_at":"2026-08-06T19:57:25.791500+00:00","description":"\nIncorrect boundary conditions in the Audio/Video: cubeb component. This\nvulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR\n140.13, Thunderbird 153, and Thunderbird 140.13.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-16350","https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16350","https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16350"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-16349","published":"2026-07-21T13:17:00","updated_at":"2026-08-06T19:57:21.352894+00:00","description":"\nSame-origin policy bypass in the DOM: Navigation component. This\nvulnerability was fixed in Firefox 153, Firefox ESR 115.38, Firefox ESR\n140.13, Thunderbird 153, and Thunderbird 140.13.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"mozjs* contain a copy of the SpiderMonkey JavaScript engine. It\nis not feasible to backport security fixes to the mozjs*\npackages, as such, marking them as ignored.\nstarting with Ubuntu 22.04, the firefox package is just a script\nthat installs the Firefox snap\nstarting with Ubuntu 24.04, the thunderbird package is just a\nscript that installs the Thunderbird snap"}],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-16349","https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/#CVE-2026-16349","https://www.mozilla.org/en-US/security/advisories/mfsa2026-70/#CVE-2026-16349"],"bugs":[""],"patches":{"firefox":[],"thunderbird":[],"mozjs38":[],"mozjs52":[],"mozjs68":[],"mozjs78":[],"mozjs91":[],"mozjs102":[],"mozjs115":[]},"tags":{},"packages":[{"name":"firefox","source":"https://ubuntu.com/security/cve?package=firefox","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=firefox","debian":"https://tracker.debian.org/pkg/firefox","statuses":[{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"thunderbird","source":"https://ubuntu.com/security/cve?package=thunderbird","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=thunderbird","debian":"https://tracker.debian.org/pkg/thunderbird","statuses":[{"release_codename":"jammy","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs38","source":"https://ubuntu.com/security/cve?package=mozjs38","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs38","debian":"https://tracker.debian.org/pkg/mozjs38","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs52","source":"https://ubuntu.com/security/cve?package=mozjs52","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs52","debian":"https://tracker.debian.org/pkg/mozjs52","statuses":[{"release_codename":"bionic","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs68","source":"https://ubuntu.com/security/cve?package=mozjs68","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs68","debian":"https://tracker.debian.org/pkg/mozjs68","statuses":[{"release_codename":"focal","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs78","source":"https://ubuntu.com/security/cve?package=mozjs78","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs78","debian":"https://tracker.debian.org/pkg/mozjs78","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs91","source":"https://ubuntu.com/security/cve?package=mozjs91","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs91","debian":"https://tracker.debian.org/pkg/mozjs91","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs102","source":"https://ubuntu.com/security/cve?package=mozjs102","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs102","debian":"https://tracker.debian.org/pkg/mozjs102","statuses":[{"release_codename":"jammy","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mozjs115","source":"https://ubuntu.com/security/cve?package=mozjs115","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mozjs115","debian":"https://tracker.debian.org/pkg/mozjs115","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"ignored","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59845","published":"2026-07-21T12:18:00","updated_at":"2026-08-31T13:59:24.909408+00:00","description":"\nA flaw was found in libssh. When ProxyCommand is used, an unchecked fork()\nfailure can be stored as process ID -1; during cleanup, signals may then be\nsent across the caller's accessible process tree, leading to local denial\nof service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59845","https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/","https://www.libssh.org/security/advisories/CVE-2026-59845.txt","https://ubuntu.com/security/notices/USN-8699-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142537"],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?id=53b8152623290c69657a6774d96888b876e6061f"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"upstream","status":"released","description":"0.12.1-1","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.9.6-2ubuntu0.22.04.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.10.6-2ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.11.3-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needed","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needed","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8699-1"],"notices":[{"id":"USN-8699-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-31T11:58:26.621286","description":"It was discovered that libssh had a stack buffer overflow in its SFTP\nserver when constructing directory listing entries for long filenames. An\nattacker could possibly use this issue to cause libssh to crash or execute\narbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15370)\n\nIt was discovered that libssh did not correctly handle SSH channel open\nmessages advertising a zero maximum packet size. An authenticated remote\nattacker could possibly use this issue to cause libssh to consume excessive\nCPU resources, leading to a denial of service. (CVE-2026-59843)\n\nIt was discovered that libssh did not correctly limit SFTP read request\nlengths in its server implementation. An authenticated remote attacker\ncould possibly use this issue to cause libssh to allocate excessive memory,\nleading to a denial of service. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-59844)\n\nIt was discovered that libssh did not correctly handle ProxyCommand fork()\nfailures. A local attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-59845)\n\nIt was discovered that libssh did not correctly sanitize shell\nmetacharacters when expanding usernames in ProxyCommand strings. An\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-59846)\n\nIt was discovered that libssh had incorrect AES-GCM tag verification when\nbuilt with the OpenSSL backend. A machine-in-the-middle attacker could\npossibly use this issue to modify encrypted traffic without detection.\n(CVE-2026-59847)\n\nIt was discovered that libssh did not correctly handle SFTP server\nresponses for unknown request IDs. An attacker could possibly use this\nissue to cause libssh to use excessive memory, leading to a denial of\nservice. (CVE-2026-59848)\n\nIt was discovered that libssh had logic errors in certificate-based\nauthentication that could cause clients to loop indefinitely when\ncertificates were rejected. An attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-59849)\n\nIt was discovered that libssh could invoke data callbacks on channels after\nthey had been closed. An attacker could possibly use this issue to cause\nlibssh to crash or execute arbitrary code. (CVE-2026-59850)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.8","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.5","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"}],"resolute":[{"name":"libssh","version":"0.11.3-1ubuntu2.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-59846","CVE-2026-59847","CVE-2026-59845","CVE-2026-59844","CVE-2026-59848","CVE-2026-15370","CVE-2026-59849","CVE-2026-59850","CVE-2026-59843"]}]},{"id":"CVE-2026-59844","published":"2026-07-21T12:18:00","updated_at":"2026-08-31T13:50:35.096377+00:00","description":"\nA flaw was found in libssh. A remote authenticated client can issue\nSSH_FXP_READ requests with an arbitrarily large length, causing a libssh\nSFTP server to allocate excessive memory and potentially exhaust it through\nrepeated requests.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in 0.11.0 by:\nhttps://github.com/libssh/libssh-mirror/commit/f8bfb5a7a1e5b1a0a910c128e827a1391ddde452"}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59844","https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/","https://www.libssh.org/security/advisories/CVE-2026-59844.txt","https://ubuntu.com/security/notices/USN-8699-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142537"],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?id=2544f22733ffcd59a2e51e2950f80901d063b946"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.11.3-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.12.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-8699-1"],"notices":[{"id":"USN-8699-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-31T11:58:26.621286","description":"It was discovered that libssh had a stack buffer overflow in its SFTP\nserver when constructing directory listing entries for long filenames. An\nattacker could possibly use this issue to cause libssh to crash or execute\narbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15370)\n\nIt was discovered that libssh did not correctly handle SSH channel open\nmessages advertising a zero maximum packet size. An authenticated remote\nattacker could possibly use this issue to cause libssh to consume excessive\nCPU resources, leading to a denial of service. (CVE-2026-59843)\n\nIt was discovered that libssh did not correctly limit SFTP read request\nlengths in its server implementation. An authenticated remote attacker\ncould possibly use this issue to cause libssh to allocate excessive memory,\nleading to a denial of service. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-59844)\n\nIt was discovered that libssh did not correctly handle ProxyCommand fork()\nfailures. A local attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-59845)\n\nIt was discovered that libssh did not correctly sanitize shell\nmetacharacters when expanding usernames in ProxyCommand strings. An\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-59846)\n\nIt was discovered that libssh had incorrect AES-GCM tag verification when\nbuilt with the OpenSSL backend. A machine-in-the-middle attacker could\npossibly use this issue to modify encrypted traffic without detection.\n(CVE-2026-59847)\n\nIt was discovered that libssh did not correctly handle SFTP server\nresponses for unknown request IDs. An attacker could possibly use this\nissue to cause libssh to use excessive memory, leading to a denial of\nservice. (CVE-2026-59848)\n\nIt was discovered that libssh had logic errors in certificate-based\nauthentication that could cause clients to loop indefinitely when\ncertificates were rejected. An attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-59849)\n\nIt was discovered that libssh could invoke data callbacks on channels after\nthey had been closed. An attacker could possibly use this issue to cause\nlibssh to crash or execute arbitrary code. (CVE-2026-59850)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.8","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.5","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"}],"resolute":[{"name":"libssh","version":"0.11.3-1ubuntu2.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-59846","CVE-2026-59847","CVE-2026-59845","CVE-2026-59844","CVE-2026-59848","CVE-2026-15370","CVE-2026-59849","CVE-2026-59850","CVE-2026-59843"]}]},{"id":"CVE-2026-59843","published":"2026-07-21T12:18:00","updated_at":"2026-08-31T13:53:04.327751+00:00","description":"\nA flaw was found in libssh. A remote authenticated peer can advertise a\nzero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel\nwrites to loop indefinitely and consume CPU, leading to denial of service.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"While this was mentioned in the 0.12.1 release notes, it was\naccidentally omitted and was included in 0.12.2 instead."}],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59843","https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/","https://www.libssh.org/security/advisories/CVE-2026-59843.txt","https://ubuntu.com/security/notices/USN-8699-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142537"],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?id=3f785905760d2e2a87037285ab85b37b9924e409","upstream: https://git.libssh.org/projects/libssh.git/commit/?id=006ddd503566ee13e00db42bc111e898388f8664"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"0.9.6-2ubuntu0.22.04.8","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"0.10.6-2ubuntu0.5","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"0.11.3-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.12.2-1","component":null,"pocket":"security"}]}],"notices_ids":["USN-8699-1"],"notices":[{"id":"USN-8699-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-31T11:58:26.621286","description":"It was discovered that libssh had a stack buffer overflow in its SFTP\nserver when constructing directory listing entries for long filenames. An\nattacker could possibly use this issue to cause libssh to crash or execute\narbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15370)\n\nIt was discovered that libssh did not correctly handle SSH channel open\nmessages advertising a zero maximum packet size. An authenticated remote\nattacker could possibly use this issue to cause libssh to consume excessive\nCPU resources, leading to a denial of service. (CVE-2026-59843)\n\nIt was discovered that libssh did not correctly limit SFTP read request\nlengths in its server implementation. An authenticated remote attacker\ncould possibly use this issue to cause libssh to allocate excessive memory,\nleading to a denial of service. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-59844)\n\nIt was discovered that libssh did not correctly handle ProxyCommand fork()\nfailures. A local attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-59845)\n\nIt was discovered that libssh did not correctly sanitize shell\nmetacharacters when expanding usernames in ProxyCommand strings. An\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-59846)\n\nIt was discovered that libssh had incorrect AES-GCM tag verification when\nbuilt with the OpenSSL backend. A machine-in-the-middle attacker could\npossibly use this issue to modify encrypted traffic without detection.\n(CVE-2026-59847)\n\nIt was discovered that libssh did not correctly handle SFTP server\nresponses for unknown request IDs. An attacker could possibly use this\nissue to cause libssh to use excessive memory, leading to a denial of\nservice. (CVE-2026-59848)\n\nIt was discovered that libssh had logic errors in certificate-based\nauthentication that could cause clients to loop indefinitely when\ncertificates were rejected. An attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-59849)\n\nIt was discovered that libssh could invoke data callbacks on channels after\nthey had been closed. An attacker could possibly use this issue to cause\nlibssh to crash or execute arbitrary code. (CVE-2026-59850)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.8","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.5","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"}],"resolute":[{"name":"libssh","version":"0.11.3-1ubuntu2.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-59846","CVE-2026-59847","CVE-2026-59845","CVE-2026-59844","CVE-2026-59848","CVE-2026-15370","CVE-2026-59849","CVE-2026-59850","CVE-2026-59843"]}]},{"id":"CVE-2026-59842","published":"2026-07-21T12:18:00","updated_at":"2026-08-25T09:17:51.227178+00:00","description":"\nA flaw was found in libssh. During server-side GSSAPI key exchange, a\nclient-supplied Curve25519 public key shorter than the expected length is\ncopied without proper length validation, leading to an out-of-bounds heap\nread. This could allow a remote unauthenticated attacker to disclose small\namounts of server memory.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"Introduced in 0.12.0 with:\nhttps://git.libssh.org/projects/libssh.git/commit/?id=88c2ea6752fab7b3da9cc4c51eaf632361a44080"}],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.7,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59842","https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/","https://www.libssh.org/security/advisories/CVE-2026-59842.txt"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142537"],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?id=5568ae6c5a1adcb008d044985fe5f1d1567bc610"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"bionic","status":"not-affected","description":"0.12.0+ only","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"0.12.0+ only","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"0.12.0+ only","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"0.12.0+ only","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"0.12.0+ only","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.12.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"0.12.0+ only","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-16461","published":"2026-07-21T12:17:00","updated_at":"2026-08-06T19:57:32.913086+00:00","description":"\nA stack-based buffer overflow was found in rpcbind's rpcinfo utility. In\nrpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote\nRPCBPROC_DUMP reply are written into a fixed-size stack buffer without\nbounds checking. A user or administrator who runs `rpcinfo -s` against a\nmalicious or compromised rpcbind endpoint could experience a crash or\ndenial of service of the rpcinfo client.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-16461","https://bugzilla.redhat.com/show_bug.cgi?id=2502719"],"bugs":[""],"patches":{"rpcbind":[]},"tags":{},"packages":[{"name":"rpcbind","source":"https://ubuntu.com/security/cve?package=rpcbind","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rpcbind","debian":"https://tracker.debian.org/pkg/rpcbind","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15370","published":"2026-07-21T09:16:00","updated_at":"2026-08-31T14:03:48.286864+00:00","description":"\nA flaw was found in libssh. During SFTP server directory listing, the\nlongname field is constructed with unsafe concatenation into a fixed-size\nstack buffer. When a client causes the server to list attacker-controlled\nfilenames, sufficiently long names can overflow that stack buffer and may\nlead to crashes or possible code execution on the server.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"introduced in libssh 0.11.0 with the following:\nhttps://github.com/libssh/libssh-mirror/commit/5ea54c8159f923b53070ecaf6329330ed60c07dc\npreviously, the code was present in the examples directory only\nwhich is not shipped in Ubuntu packaging."}],"codename":null,"priority":"medium","cvss3":6.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":6.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15370","https://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/","https://www.libssh.org/security/advisories/CVE-2026-15370.txt","https://ubuntu.com/security/notices/USN-8699-1"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142537"],"patches":{"libssh":["upstream: https://git.libssh.org/projects/libssh.git/commit/?id=4f0c400929d3aa1f505c5545703107e1c26ba24c","upstream: https://git.libssh.org/projects/libssh.git/commit/?id=770eafb74b23814815d1246249f5ce42fb92c7ba"]},"tags":{},"packages":[{"name":"libssh","source":"https://ubuntu.com/security/cve?package=libssh","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libssh","debian":"https://tracker.debian.org/pkg/libssh","statuses":[{"release_codename":"resolute","status":"released","description":"0.11.3-1ubuntu2.1","component":null,"pocket":"security"},{"release_codename":"bionic","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"focal","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"code not present","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.12.1-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"not-affected","description":"code not present","component":null,"pocket":"security"}]}],"notices_ids":["USN-8699-1"],"notices":[{"id":"USN-8699-1","title":"libssh vulnerabilities","summary":"Several security issues were fixed in libssh.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-08-31T11:58:26.621286","description":"It was discovered that libssh had a stack buffer overflow in its SFTP\nserver when constructing directory listing entries for long filenames. An\nattacker could possibly use this issue to cause libssh to crash or execute\narbitrary code. This issue only affected Ubuntu 26.04 LTS. (CVE-2026-15370)\n\nIt was discovered that libssh did not correctly handle SSH channel open\nmessages advertising a zero maximum packet size. An authenticated remote\nattacker could possibly use this issue to cause libssh to consume excessive\nCPU resources, leading to a denial of service. (CVE-2026-59843)\n\nIt was discovered that libssh did not correctly limit SFTP read request\nlengths in its server implementation. An authenticated remote attacker\ncould possibly use this issue to cause libssh to allocate excessive memory,\nleading to a denial of service. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-59844)\n\nIt was discovered that libssh did not correctly handle ProxyCommand fork()\nfailures. A local attacker could possibly use this issue to cause a denial\nof service. (CVE-2026-59845)\n\nIt was discovered that libssh did not correctly sanitize shell\nmetacharacters when expanding usernames in ProxyCommand strings. An\nattacker could possibly use this issue to obtain sensitive information.\n(CVE-2026-59846)\n\nIt was discovered that libssh had incorrect AES-GCM tag verification when\nbuilt with the OpenSSL backend. A machine-in-the-middle attacker could\npossibly use this issue to modify encrypted traffic without detection.\n(CVE-2026-59847)\n\nIt was discovered that libssh did not correctly handle SFTP server\nresponses for unknown request IDs. An attacker could possibly use this\nissue to cause libssh to use excessive memory, leading to a denial of\nservice. (CVE-2026-59848)\n\nIt was discovered that libssh had logic errors in certificate-based\nauthentication that could cause clients to loop indefinitely when\ncertificates were rejected. An attacker could possibly use this issue to\ncause a denial of service. This issue only affected Ubuntu 26.04 LTS.\n(CVE-2026-59849)\n\nIt was discovered that libssh could invoke data callbacks on channels after\nthey had been closed. An attacker could possibly use this issue to cause\nlibssh to crash or execute arbitrary code. (CVE-2026-59850)","is_hidden":false,"release_packages":{"jammy":[{"name":"libssh","version":"0.9.6-2ubuntu0.22.04.8","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-dev","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-doc","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.9.6-2ubuntu0.22.04.8","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.9.6-2ubuntu0.22.04.8","pocket":"security"}],"noble":[{"name":"libssh","version":"0.10.6-2ubuntu0.5","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-dev","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-doc","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-gcrypt-4","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"},{"name":"libssh-gcrypt-dev","version":"0.10.6-2ubuntu0.5","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.10.6-2ubuntu0.5","pocket":"security"}],"resolute":[{"name":"libssh","version":"0.11.3-1ubuntu2.1","description":"A tiny C SSH library","is_source":true},{"name":"libssh-4","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"},{"name":"libssh-dev","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"},{"name":"libssh-doc","version":"0.11.3-1ubuntu2.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/libssh","version_link":"https://launchpad.net/ubuntu/+source/libssh/0.11.3-1ubuntu2.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-59846","CVE-2026-59847","CVE-2026-59845","CVE-2026-59844","CVE-2026-59848","CVE-2026-15370","CVE-2026-59849","CVE-2026-59850","CVE-2026-59843"]}]},{"id":"CVE-2026-8593","published":"2026-07-21T08:16:00","updated_at":"2026-08-06T19:59:03.343881+00:00","description":"\nImproper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9,\n2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users\nwithout permissions to view and modify BI packs and rules","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-8593"],"bugs":[""],"patches":{"check-mk":[]},"tags":{},"packages":[{"name":"check-mk","source":"https://ubuntu.com/security/cve?package=check-mk","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=check-mk","debian":"https://tracker.debian.org/pkg/check-mk","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15812","published":"2026-07-21T06:16:00","updated_at":"2026-08-06T19:57:08.220653+00:00","description":"\nA vulnerability was found in the internal Access Control List (ACL)\nsubsystem of kronosnet (Version affected: <= 1.34). When the framework is\nexplicitly configured to manage dynamic links (accepting network traffic\nfrom any IP address) without network payload encryption, the validation\narchitecture implicitly trusts the link ID provided within incoming data\npackets. A remote, unauthenticated attacker can exploit this lack of\nvalidation by spoofing a legitimate link ID inside crafted network frames.\nThis allows the attacker to fully bypass the ACL framework and inject\narbitrary data packets into the application layer, potentially leading to\ndata corruption or service instabilities.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15812"],"bugs":[""],"patches":{"kronosnet":[]},"tags":{},"packages":[{"name":"kronosnet","source":"https://ubuntu.com/security/cve?package=kronosnet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kronosnet","debian":"https://tracker.debian.org/pkg/kronosnet","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-15811","published":"2026-07-21T06:16:00","updated_at":"2026-08-07T07:13:58.013022+00:00","description":"\nA vulnerability was found in kronosnet's (version <=1.34) cryptographic\nconfiguration management. The framework does not correctly zero-out or wipe\nsensitive memory segments after executing changes to its cryptographic\nconfiguration. This omission leaves raw encryption keys resident in memory\nafter the associated structures are freed. A local attacker capable of\nleveraging memory disclosure techniques could exploit this flaw to retrieve\nthe active encryption key, allowing them to decrypt cluster network\ncommunications or inject malicious packets to cause severe\nhigh-availability cluster instability.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-15811","https://bugzilla.redhat.com/show_bug.cgi?id=2500849","https://access.redhat.com/security/cve/CVE-2026-15811"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142847"],"patches":{"kronosnet":[]},"tags":{},"packages":[{"name":"kronosnet","source":"https://ubuntu.com/security/cve?package=kronosnet","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=kronosnet","debian":"https://tracker.debian.org/pkg/kronosnet","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-63729","published":"2026-07-21T03:16:00","updated_at":"2026-08-06T19:58:58.114877+00:00","description":"\nThe SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by\ndownstream consumers such as GNOME Evince contains a heap use-after-free\nvulnerability that allows attackers to crash applications or potentially\nexecute arbitrary code by supplying a malformed .synctex or .synctex.gz\nfile. A malformed SyncTeX file can construct a ref node with a NULL parent\npointer, causing the replacement routine to fail to detach the node from\nits sibling chain, which triggers recursive freeing of live tree nodes and\nleaves dangling pointers that are later accessed by the parser during\ndocument load.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.6,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH","baseScore":6.6,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-63729","https://fatihhcelik.github.io/posts/evince-synctex-heap-use-after-free/"],"bugs":[""],"patches":{"texlive-bin":[]},"tags":{},"packages":[{"name":"texlive-bin","source":"https://ubuntu.com/security/cve?package=texlive-bin","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=texlive-bin","debian":"https://tracker.debian.org/pkg/texlive-bin","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"2026.20260303.78225+ds-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55833","published":"2026-07-21T00:17:00","updated_at":"2026-08-06T19:58:27.856653+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty SPDY\nheader decoding continues inflating zlib-compressed header blocks after the\nraw header parser has exceeded `maxHeaderSize` and marked the frame\ntruncated in `SpdyFrameCodec`, allowing a remote peer to send a small\ncompressed `HEADERS` block that expands into much larger raw header data\nand causes compression-amplified CPU and allocation churn. This issue is\nfixed in versions 4.1.136.Final and 4.2.16.Final.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55833","https://github.com/netty/netty/security/advisories/GHSA-mvh2-crg5-v77c","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b (netty-4.2.16.Final)","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 (netty-4.1.136.Final)"],"bugs":[""],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55831","published":"2026-07-21T00:17:00","updated_at":"2026-08-06T19:58:27.856653+00:00","description":"\nNetty is a network application framework for development of protocol\nservers and clients. Prior to 4.1.136.Final and 4.2.16.Final, Netty's SPDY\nSETTINGS decoder accepts a peer-declared SETTINGS entry count up to the\n24-bit frame-length limit and materializes every unique setting ID in\n`DefaultSpdySettingsFrame`, allowing a remote SPDY/3.1 peer to send a\nsyntactically valid roughly 2 MiB SETTINGS frame that creates 262144 map\nentries and amplifies network input into heap growth and ordered-map\ninsertion work. This issue is fixed in versions 4.1.136.Final and\n4.2.16.Final.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55831","https://github.com/netty/netty/security/advisories/GHSA-6jqx-86gh-f27w","https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b (netty-4.2.16.Final)","https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 (netty-4.1.136.Final)"],"bugs":[""],"patches":{"netty":[]},"tags":{},"packages":[{"name":"netty","source":"https://ubuntu.com/security/cve?package=netty","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=netty","debian":"https://tracker.debian.org/pkg/netty","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-64624","published":"2026-07-20T22:17:00","updated_at":"2026-08-06T19:59:07.741685+00:00","description":"\nFreeRDP before 3.28.0 treats lines beginning with forward slash in RDP\nfiles as raw command-line options, exposing the entire CLI parser surface\nto untrusted files. Attackers can craft malicious RDP files with /rdp2tcp,\n/cert:ignore, or /drive options to execute arbitrary commands, bypass\ncertificate validation, or expose local filesystems without user\ninteraction.","ubuntu_description":"","notes":[{"author":"mdeslaur","note":"USN-8410-1 released an update for this issue. At the time of USN\npublication, this issue didn't have a CVE number."}],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-64624","https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rq8f-9xjh-pr3m","https://ubuntu.com/security/notices/USN-8410-1"],"bugs":[""],"patches":{"freerdp":[],"freerdp2":[],"freerdp3":[]},"tags":{},"packages":[{"name":"freerdp","source":"https://ubuntu.com/security/cve?package=freerdp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp","debian":"https://tracker.debian.org/pkg/freerdp","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp2","source":"https://ubuntu.com/security/cve?package=freerdp2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp2","debian":"https://tracker.debian.org/pkg/freerdp2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"freerdp3","source":"https://ubuntu.com/security/cve?package=freerdp3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=freerdp3","debian":"https://tracker.debian.org/pkg/freerdp3","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"3.30.0+dfsg-0ubuntu0.24.04.1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"3.30.0+dfsg-0ubuntu0.26.04.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.28.0+dfsg-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-58624","published":"2026-07-20T21:16:00","updated_at":"2026-08-06T19:58:40.162241+00:00","description":"\nImproper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD\nis a Java library for client-side and server-side SSH.\nComponent org.apache.sshd:sshd-git provides though its GitPgmCommandFactory\na way to configure an Apache MINA SSHD server such that SSH clients can\nremotely execute git commands via the JGit library on git repositories\nstored on the server.\nThis GitPgmCommandFactory allowed a user authenticated via SSH to run any\nJGit command available, including commands that could write files at\narbitrary places such as git archive with the --output option.\nAffected are SSH servers implemented with Apache MINA SSHD and using the\nGitPgmCommandFactory. If the GitPgmCommandFactory is not configured on the\nserver, the server is not affected.\nIt is recommended to upgrade affected servers to Apache MINA SSHD 2.19.0 or\n3.0.0-M5, which fix this issue.\nThe issue is fixed by restricting the available commands to a small\nwhitelist of uncritical commands (such as git log). git archive is also\nallowed, but its --output argument is ignored and the archive is always\nsent through the SSH channel to the client.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.4,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58624","https://www.openwall.com/lists/oss-security/2026/07/20/18"],"bugs":[""],"patches":{"mina":[],"mina2":[]},"tags":{},"packages":[{"name":"mina","source":"https://ubuntu.com/security/cve?package=mina","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mina","debian":"https://tracker.debian.org/pkg/mina","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mina2","source":"https://ubuntu.com/security/cve?package=mina2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mina2","debian":"https://tracker.debian.org/pkg/mina2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-56624","published":"2026-07-20T21:16:00","updated_at":"2026-08-06T19:58:40.162241+00:00","description":"\nImproper certificate validation in Apache MINA SSHD (server-side). Apache\nMINA SSHD is a Java library for client-side and server-side SSH.\nServer-side OpenSSH user certificate validation during user authentication\nin an Apache MINA SSHD server did not check for the unsupported\nforce-command or verify-required options that could be embedded in the\ncertificate, nor did it validate these options. As a result it was possible\nthat a user could authenticate with such a certificate that included a\nforce-command option but still was able to execute other commands. What\nother command exactly would be available to the user depends on the\nimplementation of the server.\nThis issue is fixed in Apache MINA SSHD 2.19.0 and 3.0.0-M5. Applications\nare advised to upgrade to these versions.\nThe fix rejects OpenSSH user certificates that include these options, since\nApache MINA SSHD implements neither force-command nor\nsk-*-cert-v01@openssh.com user certificates (which are the only ones for\nwhich verify-required would make sense).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56624","https://www.openwall.com/lists/oss-security/2026/07/20/17"],"bugs":[""],"patches":{"mina":[],"mina2":[]},"tags":{},"packages":[{"name":"mina","source":"https://ubuntu.com/security/cve?package=mina","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mina","debian":"https://tracker.debian.org/pkg/mina","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"mina2","source":"https://ubuntu.com/security/cve?package=mina2","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=mina2","debian":"https://tracker.debian.org/pkg/mina2","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":7000,"limit":20,"total_results":79316}