{"cves":[{"id":"CVE-2026-61863","published":"2026-07-15T12:18:00","updated_at":"2026-09-15T16:19:53.261342+00:00","description":"\nImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memory\nleak in the TIFF encoder that occurs when a temporary file cannot be\ncreated, resulting in a small memory leak.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":2.9,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-61863","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9","https://ubuntu.com/security/notices/USN-8739-1","https://ubuntu.com/security/notices/USN-8739-2"],"bugs":[""],"patches":{"imagemagick":["upstream: https://github.com/ImageMagick/ImageMagick/commit/f3ff3afee942a19e3041568bfa740d48213a3dec"]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"upstream","status":"released","description":"8:7.1.2.26+dfsg1-1","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","component":null,"pocket":"esm-apps"},{"release_codename":"noble","status":"released","description":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","component":null,"pocket":"esm-apps"},{"release_codename":"bionic","status":"released","description":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","component":null,"pocket":"esm-infra"},{"release_codename":"focal","status":"released","description":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","component":null,"pocket":"esm-apps"},{"release_codename":"jammy","status":"released","description":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","component":null,"pocket":"esm-apps"},{"release_codename":"trusty","status":"released","description":"8:6.7.7.10-6ubuntu3.13+esm25","component":null,"pocket":"esm-infra-legacy"},{"release_codename":"xenial","status":"released","description":"8:6.8.9.9-7ubuntu5.16+esm24","component":null,"pocket":"esm-infra-legacy"}]}],"notices_ids":["USN-8739-1","USN-8739-2"],"notices":[{"id":"USN-8739-1","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-08T18:30:19.705108","description":"It was discovered that ImageMagick incorrectly handled certain images. An\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366, CVE-2026-56368,\nCVE-2026-56371, CVE-2026-56373)\n\nIt was discovered that ImageMagick incorrectly handled certain images. An\nattacker could possibly use this issue to cause a denial of service or\nexecute arbitrary code. This issue only affected Ubuntu 22.04 LTS and\nUbuntu 26.04 LTS. (CVE-2026-56370)\n\nIt was discovered that ImageMagick incorrectly handled certain images. An\nattacker could possibly use this issue to cause a denial of service or\nexpose sensitive information. This issue only affected Ubuntu 14.04 LTS,\nUbuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS.\n(CVE-2026-56378)\n\nIt was discovered that ImageMagick incorrectly handled certain images. An\nattacker could possibly use this issue to execute arbitrary code. This\nissue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,\nUbuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56379)\n\nIt was discovered that ImageMagick incorrectly handled memory allocation in\ncertain operations. An attacker could possibly use this issue to cause a\ndenial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04\nLTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS.\n(CVE-2026-61465)\n\nIt was discovered that ImageMagick incorrectly handled certain images. An\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-61857)\n\nIt was discovered that ImageMagick incorrectly handled certain images. An\nattacker could possibly use this issue to cause a denial of service.\n(CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61870)\n\nIt was discovered that ImageMagick incorrectly handled certain images. An\nattacker could possibly use this issue to cause a denial of service. This\nissue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\nUbuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61866)\n\nIt was discovered that ImageMagick incorrectly handled certain images on\n32-bit systems. An attacker could possibly use this issue to cause a denial\nof service or execute arbitrary code. This issue only affected Ubuntu 16.04\nLTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04\nLTS. (CVE-2026-62946)","is_hidden":false,"release_packages":{"bionic":[{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"imagemagick-6-common","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"imagemagick-6-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"imagemagick-6.q16","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"imagemagick-common","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"imagemagick-doc","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libimage-magick-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libimage-magick-q16-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagick++-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagick++-6.q16-7","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagick++-6.q16hdri-7","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagick++-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickcore-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickcore-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickcore-6.q16-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickcore-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickcore-6.q16hdri-3-extra","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickcore-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickwand-6-headers","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickwand-6.q16-3","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickwand-6.q16hdri-3","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"libmagickwand-dev","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"},{"name":"perlmagick","version":"8:6.9.7.4+dfsg-16ubuntu6.15+esm16","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra"}],"focal":[{"name":"imagemagick","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6-common","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6-doc","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6.q16","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-common","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-doc","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-perl","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-q16-perl","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6-headers","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16-8","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16hdri-8","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-dev","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6-headers","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16-6","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16-6-extra","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16hdri-6","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16hdri-6-extra","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-dev","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6-headers","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16-6","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16hdri-6","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-dev","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"perlmagick","version":"8:6.9.10.23+dfsg-2.1ubuntu11.11+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"}],"jammy":[{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6-common","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6-doc","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6.q16","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-common","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-doc","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-perl","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-q16-perl","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6-headers","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16-8","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16hdri-8","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-dev","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6-headers","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16-6","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16-6-extra","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16hdri-6","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16hdri-6-extra","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-dev","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6-headers","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16-6","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16hdri-6","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-dev","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"perlmagick","version":"8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm14","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"}],"resolute":[{"name":"imagemagick","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-7-common","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-7-doc","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-7.q16","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-7.q16hdri","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-perl","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-q16-perl","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-q16hdri-perl","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-7-headers","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-7.q16-5","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-7.q16-dev","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-7.q16hdri-5","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-7.q16hdri-dev","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-dev","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-7-arch-config","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-7-headers","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-7.q16-10","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-7.q16-10-extra","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-7.q16-dev","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-7.q16hdri-10","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-7.q16hdri-10-extra","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-7.q16hdri-dev","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-dev","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-7-headers","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-7.q16-10","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-7.q16-dev","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-7.q16hdri-10","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-7.q16hdri-dev","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-dev","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"perlmagick","version":"8:7.1.2.18+dfsg1-1ubuntu0.1~esm2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"}],"trusty":[{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.13+esm25","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"imagemagick-common","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"imagemagick-doc","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagick++-dev","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagick++5","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickcore-dev","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickcore5","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickcore5-extra","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickwand-dev","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickwand5","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"perlmagick","version":"8:6.7.7.10-6ubuntu3.13+esm25","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"}],"xenial":[{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.16+esm24","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"imagemagick-6.q16","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"imagemagick-common","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"imagemagick-doc","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libimage-magick-perl","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libimage-magick-q16-perl","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagick++-6-headers","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagick++-6.q16-5v5","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagick++-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagick++-dev","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickcore-6-arch-config","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickcore-6-headers","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickcore-6.q16-2","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickcore-6.q16-2-extra","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickcore-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickcore-dev","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickwand-6-headers","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickwand-6.q16-2","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickwand-6.q16-dev","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"libmagickwand-dev","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"},{"name":"perlmagick","version":"8:6.8.9.9-7ubuntu5.16+esm24","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-infra-legacy"}]},"type":"USN","cves_ids":["CVE-2026-61866","CVE-2026-61863","CVE-2026-61864","CVE-2026-61865","CVE-2026-56378","CVE-2026-56379","CVE-2026-56371","CVE-2026-62946","CVE-2026-56370","CVE-2026-61870","CVE-2026-61857","CVE-2026-61465","CVE-2026-56368","CVE-2026-56373","CVE-2026-56366"]},{"id":"USN-8739-2","title":"ImageMagick vulnerabilities","summary":"Several security issues were fixed in ImageMagick.","instructions":"In general, a standard system update will make all the necessary changes.","references":[],"published":"2026-09-14T18:22:59.694988","description":"USN-8739-1 fixed vulnerabilities in ImageMagick. This update provides the\ncorresponding fixes for Ubuntu 24.04 LTS.\n\nOriginal advisory details:\n\n It was discovered that ImageMagick incorrectly handled certain images. An\n attacker could possibly use this issue to cause a denial of service. This\n issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,\n Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56366, CVE-2026-56368,\n CVE-2026-56371, CVE-2026-56373)\n\n It was discovered that ImageMagick incorrectly handled certain images. An\n attacker could possibly use this issue to cause a denial of service or\n execute arbitrary code. This issue only affected Ubuntu 22.04 LTS and\n Ubuntu 26.04 LTS. (CVE-2026-56370)\n\n It was discovered that ImageMagick incorrectly handled certain images. An\n attacker could possibly use this issue to cause a denial of service or\n expose sensitive information. This issue only affected Ubuntu 14.04 LTS,\n Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04\n LTS. (CVE-2026-56378)\n\n It was discovered that ImageMagick incorrectly handled certain images. An\n attacker could possibly use this issue to execute arbitrary code. This\n issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,\n Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS. (CVE-2026-56379)\n\n It was discovered that ImageMagick incorrectly handled memory allocation\n in certain operations. An attacker could possibly use this issue to cause\n a denial of service. This issue only affected Ubuntu 16.04 LTS, Ubuntu\n 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS.\n (CVE-2026-61465)\n\n It was discovered that ImageMagick incorrectly handled certain images. An\n attacker could possibly use this issue to cause a denial of service. This\n issue only affected Ubuntu 22.04 LTS and Ubuntu 26.04 LTS.\n (CVE-2026-61857)\n\n It was discovered that ImageMagick incorrectly handled certain images. An\n attacker could possibly use this issue to cause a denial of service.\n (CVE-2026-61863, CVE-2026-61864, CVE-2026-61865, CVE-2026-61870)\n\n It was discovered that ImageMagick incorrectly handled certain images. An\n attacker could possibly use this issue to cause a denial of service. This\n issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,\n Ubuntu 22.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61866)\n\n It was discovered that ImageMagick incorrectly handled certain images on\n 32-bit systems. An attacker could possibly use this issue to cause a\n denial of service or execute arbitrary code. This issue only affected\n Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,\n and Ubuntu 26.04 LTS. (CVE-2026-62946)","is_hidden":false,"release_packages":{"noble":[{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","description":"Image manipulation programs and library","is_source":true},{"name":"imagemagick","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6-common","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6-doc","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6.q16","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"imagemagick-6.q16hdri","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-perl","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-q16-perl","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libimage-magick-q16hdri-perl","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6-headers","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16-9t64","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16-dev","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16hdri-9t64","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-6.q16hdri-dev","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagick++-dev","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6-arch-config","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6-headers","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16-7-extra","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16-7t64","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16-dev","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16hdri-7-extra","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16hdri-7t64","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-6.q16hdri-dev","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickcore-dev","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6-headers","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16-7t64","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16-dev","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16hdri-7t64","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-6.q16hdri-dev","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"libmagickwand-dev","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"},{"name":"perlmagick","version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm13","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/imagemagick","version_link":null,"pocket":"esm-apps"}]},"type":"USN","cves_ids":["CVE-2026-61870","CVE-2026-61465","CVE-2026-61864","CVE-2026-61857","CVE-2026-56378","CVE-2026-61863","CVE-2026-62946","CVE-2026-56366","CVE-2026-56371","CVE-2026-56368","CVE-2026-56370","CVE-2026-61865","CVE-2026-61866","CVE-2026-56379","CVE-2026-56373"]}]},{"id":"CVE-2026-61862","published":"2026-07-15T12:18:00","updated_at":"2026-08-06T19:58:52.744443+00:00","description":"\nImageMagick before 7.1.2-26 and 6.9.13-51 contains an information\ndisclosure vulnerability: when a profile is displayed with the identify\ncommand and the profile value is not printable, a single byte at the end of\nthe profile can be printed (read past the profile boundary). This behavior\noccurs when debug output is enabled.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.9,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.9,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-61862","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx"],"bugs":[""],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:7.1.2.26+dfsg1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-61860","published":"2026-07-15T12:18:00","updated_at":"2026-08-06T19:58:47.909294+00:00","description":"\nImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free\nvulnerability that occurs when freetype initialization fails: the method\ndoes not exit and continues to use memory that was already freed. This can\nbe triggered during image processing and may lead to a denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-61860","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm"],"bugs":[""],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:7.1.2.26+dfsg1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-61859","published":"2026-07-15T12:18:00","updated_at":"2026-08-06T19:59:07.741685+00:00","description":"\nImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy\nbypass vulnerability in the -script operation due to missing security\npolicy checks. This allows reading files from paths that are otherwise\ndisallowed by the configured security policy.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-61859","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398"],"bugs":[""],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:7.1.2.26+dfsg1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-61464","published":"2026-07-15T12:18:00","updated_at":"2026-08-06T19:58:47.909294+00:00","description":"\nImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer\nover-write vulnerability that occurs when running an X11 import with a\ncrafted window title, which can result in heap memory corruption and denial\nof service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":1.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":1.8,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"HIGH","attackRequirements":"PRESENT","privilegesRequired":"HIGH","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.0,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-61464","https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr"],"bugs":[""],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"8:7.1.2.26+dfsg1-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-56375","published":"2026-07-15T12:18:00","updated_at":"2026-08-06T19:58:32.234649+00:00","description":"\nImageMagick through 7.1.2-18 contains a memory leak vulnerability in the\nASHLAR coder when an action fails. Attackers can trigger failed actions to\nexhaust memory resources and cause denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56375"],"bugs":[""],"patches":{"imagemagick":[]},"tags":{},"packages":[{"name":"imagemagick","source":"https://ubuntu.com/security/cve?package=imagemagick","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=imagemagick","debian":"https://tracker.debian.org/pkg/imagemagick","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-56136","published":"2026-07-15T12:00:00","updated_at":"2026-08-31T06:44:18.871051+00:00","description":"\nIn NTFS-3G through 2026.2.25, an out-of-bounds read exists in\nntfs_ir_nill() in libntfs-3g/index.c that allows an attacker to read\npossibly confidential information in an ntfs-3g process by crafting a\nmalicious NTFS image. This read operation is triggered by creation of a\nfile with a crafted name.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.7,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.7,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56136","https://ubuntu.com/security/notices/USN-8554-1"],"bugs":[""],"patches":{"ntfs-3g":[]},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:2021.8.22-3ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:2022.10.3-1.2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:2022.10.3-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8554-1"],"notices":[{"id":"USN-8554-1","title":"NTFS-3G vulnerabilities","summary":"Several security issues were fixed in NTFS-3G.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-16T11:44:54.560370","description":"It was discovered that NTFS-3G had a heap buffer overflow when reading\ncertain NTFS images. A local attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-42616)\n\nIt was discovered that NTFS-3G had multiple heap buffer overflows when\nprocessing certain NTFS images. A local attacker could possibly use these\nissues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618,\nCVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135)\n\nIt was discovered that NTFS-3G had out-of-bounds reads when processing\ncertain NTFS images. A local attacker could possibly use these issues to\nobtain sensitive information. (CVE-2026-46571, CVE-2026-56136)","is_hidden":false,"release_packages":{"jammy":[{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"}],"noble":[{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"}],"resolute":[{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42616","CVE-2026-56135","CVE-2026-46570","CVE-2026-56136","CVE-2026-46569","CVE-2026-46572","CVE-2026-42617","CVE-2026-46571","CVE-2026-42618"]}]},{"id":"CVE-2026-56135","published":"2026-07-15T12:00:00","updated_at":"2026-09-02T21:06:24.743192+00:00","description":"\nIn NTFS-3G through 2026.2.25, a heap-based buffer overflow exists in the\nfunction build_inherited_id() in libntfs-3g/security.c that allows an\nattacker to corrupt heap memory in the SUID-root ntfs-3g binary by crafting\na malicious NTFS image. The overflow is triggered by creating a file in a\ncrafted directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-56135","https://ubuntu.com/security/notices/USN-8554-1"],"bugs":[""],"patches":{"ntfs-3g":[]},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:2021.8.22-3ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:2022.10.3-1.2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:2022.10.3-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8554-1"],"notices":[{"id":"USN-8554-1","title":"NTFS-3G vulnerabilities","summary":"Several security issues were fixed in NTFS-3G.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-16T11:44:54.560370","description":"It was discovered that NTFS-3G had a heap buffer overflow when reading\ncertain NTFS images. A local attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-42616)\n\nIt was discovered that NTFS-3G had multiple heap buffer overflows when\nprocessing certain NTFS images. A local attacker could possibly use these\nissues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618,\nCVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135)\n\nIt was discovered that NTFS-3G had out-of-bounds reads when processing\ncertain NTFS images. A local attacker could possibly use these issues to\nobtain sensitive information. (CVE-2026-46571, CVE-2026-56136)","is_hidden":false,"release_packages":{"jammy":[{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"}],"noble":[{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"}],"resolute":[{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42616","CVE-2026-56135","CVE-2026-46570","CVE-2026-56136","CVE-2026-46569","CVE-2026-46572","CVE-2026-42617","CVE-2026-46571","CVE-2026-42618"]}]},{"id":"CVE-2026-46572","published":"2026-07-15T12:00:00","updated_at":"2026-07-16T15:01:49.434077+00:00","description":"\nIn NTFS-3G through 2026.2.25, a heap buffer overflow exists in\nntfs_ib_cut_tail() in libntfs-3g/index.c that allows an attacker to\ncorrupt heap memory in the SUID-root ntfs-3g binary by crafting a\nmalicious NTFS image. The overflow is triggered by creating a file in a\ncrafted directory.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46572","https://ubuntu.com/security/notices/USN-8554-1"],"bugs":[""],"patches":{"ntfs-3g":[]},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:2021.8.22-3ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:2022.10.3-1.2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:2022.10.3-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8554-1"],"notices":[{"id":"USN-8554-1","title":"NTFS-3G vulnerabilities","summary":"Several security issues were fixed in NTFS-3G.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-16T11:44:54.560370","description":"It was discovered that NTFS-3G had a heap buffer overflow when reading\ncertain NTFS images. A local attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-42616)\n\nIt was discovered that NTFS-3G had multiple heap buffer overflows when\nprocessing certain NTFS images. A local attacker could possibly use these\nissues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618,\nCVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135)\n\nIt was discovered that NTFS-3G had out-of-bounds reads when processing\ncertain NTFS images. A local attacker could possibly use these issues to\nobtain sensitive information. (CVE-2026-46571, CVE-2026-56136)","is_hidden":false,"release_packages":{"jammy":[{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"}],"noble":[{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"}],"resolute":[{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42616","CVE-2026-56135","CVE-2026-46570","CVE-2026-56136","CVE-2026-46569","CVE-2026-46572","CVE-2026-42617","CVE-2026-46571","CVE-2026-42618"]}]},{"id":"CVE-2026-46571","published":"2026-07-15T12:00:00","updated_at":"2026-07-16T15:01:49.434077+00:00","description":"\nIn NTFS-3G through 2026.2.25, a out-of-bounds read exists in\nntfs_fix_file_name() in libntfs-3g/reparse.c that allows an attacker to\nread possibly confidential information in ntfs-3g process memory by\ncrafting a malicious NTFS image. The out-of-bounds read is triggered by\na readlink on a corrupted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46571","https://ubuntu.com/security/notices/USN-8554-1"],"bugs":[""],"patches":{"ntfs-3g":[]},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:2021.8.22-3ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:2022.10.3-1.2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:2022.10.3-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8554-1"],"notices":[{"id":"USN-8554-1","title":"NTFS-3G vulnerabilities","summary":"Several security issues were fixed in NTFS-3G.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-16T11:44:54.560370","description":"It was discovered that NTFS-3G had a heap buffer overflow when reading\ncertain NTFS images. A local attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-42616)\n\nIt was discovered that NTFS-3G had multiple heap buffer overflows when\nprocessing certain NTFS images. A local attacker could possibly use these\nissues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618,\nCVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135)\n\nIt was discovered that NTFS-3G had out-of-bounds reads when processing\ncertain NTFS images. A local attacker could possibly use these issues to\nobtain sensitive information. (CVE-2026-46571, CVE-2026-56136)","is_hidden":false,"release_packages":{"jammy":[{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"}],"noble":[{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"}],"resolute":[{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42616","CVE-2026-56135","CVE-2026-46570","CVE-2026-56136","CVE-2026-46569","CVE-2026-46572","CVE-2026-42617","CVE-2026-46571","CVE-2026-42618"]}]},{"id":"CVE-2026-46570","published":"2026-07-15T12:00:00","updated_at":"2026-07-16T15:01:49.434077+00:00","description":"\nIn NTFS-3G through 2026.2.25, a heap buffer overflow exists in\nntfs_index_walk_down() in libntfs-3g/index.c that allows an attacker to\ncorrupt heap memory in the SUID-root ntfs-3g binary by crafting a\nmalicious NTFS image. The overflow is triggered by reading crafted file\nmetadata.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46570","https://ubuntu.com/security/notices/USN-8554-1"],"bugs":[""],"patches":{"ntfs-3g":[]},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:2021.8.22-3ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:2022.10.3-1.2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:2022.10.3-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8554-1"],"notices":[{"id":"USN-8554-1","title":"NTFS-3G vulnerabilities","summary":"Several security issues were fixed in NTFS-3G.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-16T11:44:54.560370","description":"It was discovered that NTFS-3G had a heap buffer overflow when reading\ncertain NTFS images. A local attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-42616)\n\nIt was discovered that NTFS-3G had multiple heap buffer overflows when\nprocessing certain NTFS images. A local attacker could possibly use these\nissues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618,\nCVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135)\n\nIt was discovered that NTFS-3G had out-of-bounds reads when processing\ncertain NTFS images. A local attacker could possibly use these issues to\nobtain sensitive information. (CVE-2026-46571, CVE-2026-56136)","is_hidden":false,"release_packages":{"jammy":[{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"}],"noble":[{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"}],"resolute":[{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42616","CVE-2026-56135","CVE-2026-46570","CVE-2026-56136","CVE-2026-46569","CVE-2026-46572","CVE-2026-42617","CVE-2026-46571","CVE-2026-42618"]}]},{"id":"CVE-2026-46569","published":"2026-07-15T12:00:00","updated_at":"2026-07-16T15:01:49.434077+00:00","description":"\nIn NTFS-3G through 2026.2.25, a heap buffer overflow exists in\nntfs_ib_copy_tail(), in libntfs-3g/index.c, that allows an attacker to\ncorrupt heap memory in the SUID-root ntfs-3g binary by crafting a\nmalicious NTFS image. The overflow is triggered by extending a\ndirectory, e.g., by creating a file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-46569","https://ubuntu.com/security/notices/USN-8554-1"],"bugs":[""],"patches":{"ntfs-3g":[]},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:2021.8.22-3ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:2022.10.3-1.2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:2022.10.3-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8554-1"],"notices":[{"id":"USN-8554-1","title":"NTFS-3G vulnerabilities","summary":"Several security issues were fixed in NTFS-3G.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-16T11:44:54.560370","description":"It was discovered that NTFS-3G had a heap buffer overflow when reading\ncertain NTFS images. A local attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-42616)\n\nIt was discovered that NTFS-3G had multiple heap buffer overflows when\nprocessing certain NTFS images. A local attacker could possibly use these\nissues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618,\nCVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135)\n\nIt was discovered that NTFS-3G had out-of-bounds reads when processing\ncertain NTFS images. A local attacker could possibly use these issues to\nobtain sensitive information. (CVE-2026-46571, CVE-2026-56136)","is_hidden":false,"release_packages":{"jammy":[{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"}],"noble":[{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"}],"resolute":[{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42616","CVE-2026-56135","CVE-2026-46570","CVE-2026-56136","CVE-2026-46569","CVE-2026-46572","CVE-2026-42617","CVE-2026-46571","CVE-2026-42618"]}]},{"id":"CVE-2026-42618","published":"2026-07-15T12:00:00","updated_at":"2026-07-16T15:01:49.434077+00:00","description":"\nIn NTFS-3G through 2026.2.25, a heap buffer overflow exists in\nntfs_decompress() in compress.c that allows an attacker to corrupt one\nbyte of heap memory in the SUID-root ntfs-3g binary by crafting a\nmalicious NTFS image. The overflow is triggered by reading the special\ncrafted file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42618","https://ubuntu.com/security/notices/USN-8554-1"],"bugs":[""],"patches":{"ntfs-3g":[]},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:2021.8.22-3ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:2022.10.3-1.2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:2022.10.3-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8554-1"],"notices":[{"id":"USN-8554-1","title":"NTFS-3G vulnerabilities","summary":"Several security issues were fixed in NTFS-3G.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-16T11:44:54.560370","description":"It was discovered that NTFS-3G had a heap buffer overflow when reading\ncertain NTFS images. A local attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-42616)\n\nIt was discovered that NTFS-3G had multiple heap buffer overflows when\nprocessing certain NTFS images. A local attacker could possibly use these\nissues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618,\nCVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135)\n\nIt was discovered that NTFS-3G had out-of-bounds reads when processing\ncertain NTFS images. A local attacker could possibly use these issues to\nobtain sensitive information. (CVE-2026-46571, CVE-2026-56136)","is_hidden":false,"release_packages":{"jammy":[{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"}],"noble":[{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"}],"resolute":[{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42616","CVE-2026-56135","CVE-2026-46570","CVE-2026-56136","CVE-2026-46569","CVE-2026-46572","CVE-2026-42617","CVE-2026-46571","CVE-2026-42618"]}]},{"id":"CVE-2026-42617","published":"2026-07-15T12:00:00","updated_at":"2026-07-16T15:01:49.434077+00:00","description":"\nIn NTFS-3G through 2026.2.25, a heap buffer overflow exists in\nntfs_ir_to_ib() in index.c that allows an attacker to corrupt heap\nmemory in the SUID-root ntfs-3g binary by crafting a malicious NTFS\nimage. The overflow is triggered by extending a directory, e.g., by\ncreating a file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42617","https://ubuntu.com/security/notices/USN-8554-1"],"bugs":[""],"patches":{"ntfs-3g":[]},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:2021.8.22-3ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:2022.10.3-1.2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:2022.10.3-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8554-1"],"notices":[{"id":"USN-8554-1","title":"NTFS-3G vulnerabilities","summary":"Several security issues were fixed in NTFS-3G.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-16T11:44:54.560370","description":"It was discovered that NTFS-3G had a heap buffer overflow when reading\ncertain NTFS images. A local attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-42616)\n\nIt was discovered that NTFS-3G had multiple heap buffer overflows when\nprocessing certain NTFS images. A local attacker could possibly use these\nissues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618,\nCVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135)\n\nIt was discovered that NTFS-3G had out-of-bounds reads when processing\ncertain NTFS images. A local attacker could possibly use these issues to\nobtain sensitive information. (CVE-2026-46571, CVE-2026-56136)","is_hidden":false,"release_packages":{"jammy":[{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"}],"noble":[{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"}],"resolute":[{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42616","CVE-2026-56135","CVE-2026-46570","CVE-2026-56136","CVE-2026-46569","CVE-2026-46572","CVE-2026-42617","CVE-2026-46571","CVE-2026-42618"]}]},{"id":"CVE-2026-42616","published":"2026-07-15T12:00:00","updated_at":"2026-07-16T15:01:49.434077+00:00","description":"\nIn NTFS-3G through 2026.2.25, a heap buffer overflow exists in cat() in\ncat.c that allows an attacker to corrupt heap memory in the ntfscat\nbinary by crafting a malicious NTFS image. The overflow is triggered by\nreading a file.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":null,"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42616","https://ubuntu.com/security/notices/USN-8554-1"],"bugs":[""],"patches":{"ntfs-3g":[]},"tags":{},"packages":[{"name":"ntfs-3g","source":"https://ubuntu.com/security/cve?package=ntfs-3g","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ntfs-3g","debian":"https://tracker.debian.org/pkg/ntfs-3g","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"released","description":"1:2021.8.22-3ubuntu1.4","component":null,"pocket":"security"},{"release_codename":"noble","status":"released","description":"1:2022.10.3-1.2ubuntu3.2","component":null,"pocket":"security"},{"release_codename":"resolute","status":"released","description":"1:2022.10.3-5ubuntu1.1","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":["USN-8554-1"],"notices":[{"id":"USN-8554-1","title":"NTFS-3G vulnerabilities","summary":"Several security issues were fixed in NTFS-3G.","instructions":"In general, a standard system update will make all the necessary\nchanges.","references":[],"published":"2026-07-16T11:44:54.560370","description":"It was discovered that NTFS-3G had a heap buffer overflow when reading\ncertain NTFS images. A local attacker could possibly use this issue to\nexecute arbitrary code. (CVE-2026-42616)\n\nIt was discovered that NTFS-3G had multiple heap buffer overflows when\nprocessing certain NTFS images. A local attacker could possibly use these\nissues to execute arbitrary code. (CVE-2026-42617, CVE-2026-42618,\nCVE-2026-46569, CVE-2026-46570, CVE-2026-46572, CVE-2026-56135)\n\nIt was discovered that NTFS-3G had out-of-bounds reads when processing\ncertain NTFS images. A local attacker could possibly use these issues to\nobtain sensitive information. (CVE-2026-46571, CVE-2026-56136)","is_hidden":false,"release_packages":{"jammy":[{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2021.8.22-3ubuntu1.4","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2021.8.22-3ubuntu1.4","pocket":"security"}],"noble":[{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-1.2ubuntu3.2","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-1.2ubuntu3.2","pocket":"security"}],"resolute":[{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","description":"read/write NTFS driver for FUSE","is_source":true},{"name":"libntfs-3g89t64","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":true,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"},{"name":"ntfs-3g-dev","version":"1:2022.10.3-5ubuntu1.1","is_source":false,"is_visible":false,"source_link":"https://launchpad.net/ubuntu/+source/ntfs-3g","version_link":"https://launchpad.net/ubuntu/+source/ntfs-3g/1:2022.10.3-5ubuntu1.1","pocket":"security"}]},"type":"USN","cves_ids":["CVE-2026-42616","CVE-2026-56135","CVE-2026-46570","CVE-2026-56136","CVE-2026-46569","CVE-2026-46572","CVE-2026-42617","CVE-2026-46571","CVE-2026-42618"]}]},{"id":"CVE-2026-59733","published":"2026-07-14T22:17:00","updated_at":"2026-07-16T10:55:34.092887+00:00","description":"\nRclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. Prior to 1.74.4, rclone serve restic\n--private-repos enforces authorization using the routed user path segment\nwhile building the backend object key from the raw uncleaned URL path,\nallowing an authenticated user to include .. in a request such as\n//..//config and read, overwrite, or delete another user's private\nrepository on backends that clean path components. This issue is fixed in\nversion 1.74.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59733","https://github.com/rclone/rclone/security/advisories/GHSA-fqj9-69pf-6pjg","https://github.com/rclone/rclone/commit/015fd0eba1cb138eef081517795fed47a2873f2d","https://github.com/rclone/rclone/commit/dade21c1616035b044df0eef7ee6a85aeb06a139","https://github.com/rclone/rclone/releases/tag/v1.74.4"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59732","published":"2026-07-14T22:17:00","updated_at":"2026-07-16T10:56:13.725214+00:00","description":"\nRclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. Prior to 1.74.4, rclone archive extract\ncan write extracted files outside the user-selected destination prefix when\nextracting a crafted archive containing parent path components such as ../,\nallowing creation or overwrite of sibling objects in the same bucket or\npath scope. This issue is fixed in version 1.74.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59732","https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p","https://github.com/rclone/rclone/commit/1a746732441e8158f32fab35924b23701e719a8c","https://github.com/rclone/rclone/commit/d11efe0d58fe6a2d6d90675bb9d8ee5840c51e1d","https://github.com/rclone/rclone/releases/tag/v1.74.4"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54572","published":"2026-07-14T22:17:00","updated_at":"2026-07-16T10:55:55.253395+00:00","description":"\nRclone is a command-line program to sync files and directories to and from\ndifferent cloud storage providers. Prior to 1.74.4, with -l/--links, rclone\nserializes symlinks as .rclonelink text objects and recreates them on a\nlocal destination without validating the target, allowing an\nattacker-controlled remote to plant an escaping symlink and cause a\nfollowing object write to land outside the destination with attacker-chosen\ncontents. This issue is fixed in version 1.74.4.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":7.5,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54572","https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc","https://github.com/rclone/rclone/commit/1154afebee986180b489084d38e2a0c578751498","https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265","https://github.com/rclone/rclone/releases/tag/v1.74.4"],"bugs":[""],"patches":{"rclone":[]},"tags":{},"packages":[{"name":"rclone","source":"https://ubuntu.com/security/cve?package=rclone","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=rclone","debian":"https://tracker.debian.org/pkg/rclone","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-49981","published":"2026-07-14T22:17:00","updated_at":"2026-07-17T19:35:30.817717+00:00","description":"\nTwig is a template language for PHP. Prior to 3.27.0, the per-template\nfilter, tag, and function allow-list verdict is computed when a Template\ninstance is constructed and can remain cached after sandbox state changes\nbetween renders, allowing a later sandboxed render to reuse a template that\nwas originally checked with a different or empty policy. This issue is\nfixed in version 3.27.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":8.2,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-49981","https://github.com/twigphp/Twig/commit/23eb6eb1267cb0d303b91eb5cff9b0c559c538a4","https://github.com/twigphp/Twig/releases/tag/v3.27.0","https://github.com/twigphp/Twig/security/advisories/GHSA-529h-vh3j-85hq"],"bugs":[""],"patches":{"php-twig":[],"twig":[]},"tags":{},"packages":[{"name":"php-twig","source":"https://ubuntu.com/security/cve?package=php-twig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-twig","debian":"https://tracker.debian.org/pkg/php-twig","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"twig","source":"https://ubuntu.com/security/cve?package=twig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=twig","debian":"https://tracker.debian.org/pkg/twig","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48808","published":"2026-07-14T22:17:00","updated_at":"2026-07-17T19:35:30.817717+00:00","description":"\nTwig is a template language for PHP. Prior to 3.27.0, the column filter\npasses the active sandbox state as a boolean but does not forward the\ncurrent Source to SandboxExtension::checkPropertyAllowed(), so\nSourcePolicyInterface decisions are lost and a template author can read\npublic or magic properties not allowed by the sandbox policy. This issue is\nfixed in version 3.27.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48808","https://symfony.com/blog/cve-2026-48808-sandbox-property-allowlist-bypass-via-the-column-filter-under-sourcepolicyinterface"],"bugs":[""],"patches":{"php-twig":[]},"tags":{},"packages":[{"name":"php-twig","source":"https://ubuntu.com/security/cve?package=php-twig","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=php-twig","debian":"https://tracker.debian.org/pkg/php-twig","statuses":[{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.27.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":7600,"limit":20,"total_results":79316}