{"cves":[{"id":"CVE-2026-90825","published":"2026-09-14T22:16:00","updated_at":"2026-09-17T00:23:25.822025+00:00","description":"\nA vulnerability was found in GPAC 26.07.0. Affected by this vulnerability\nis the function gf_node_unregister of the file scenegraph/base_scenegraph.c\nof the component MP4Box. The manipulation results in use after free. The\nattack is only possible with local access. The exploit has been made public\nand could be used. Upgrading to version abi-16.23 addresses this issue. The\npatch is identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading\nthe affected component is advised.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90825","https://github.com/gpac/gpac/","https://github.com/gpac/gpac/commit/9eb40df4448b88d6a6ce3454657c06f47eff0b24","https://github.com/gpac/gpac/issues/3805","https://github.com/gpac/gpac/releases/tag/abi-16.23","https://github.com/user-attachments/files/30399108/poc_09_add.zip","https://vuldb.com/cve/CVE-2026-90825","https://vuldb.com/submit/914950","https://vuldb.com/vuln/403327","https://vuldb.com/vuln/403327/cti"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-90824","published":"2026-09-14T21:17:00","updated_at":"2026-09-17T00:27:50.067215+00:00","description":"\nA vulnerability has been found in GPAC 26.07.0. Affected is the function\ngf_sg_dom_event_bubble of the file src/scenegraph/dom_events.c of the\ncomponent MP4Box. The manipulation leads to stack-based buffer overflow.\nThe attack can only be performed from a local environment. The exploit has\nbeen disclosed to the public and may be used. Upgrading to version\nabi-16.23 is able to address this issue. The identifier of the patch is\n9eb40df4448b88d6a6ce3454657c06f47eff0b24. It is recommended to upgrade the\naffected component.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.3,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90824","https://github.com/gpac/gpac/","https://github.com/gpac/gpac/commit/9eb40df4448b88d6a6ce3454657c06f47eff0b24","https://github.com/gpac/gpac/issues/3804","https://github.com/gpac/gpac/releases/tag/abi-16.23","https://github.com/user-attachments/files/30398880/poc_08_add.zip","https://vuldb.com/cve/CVE-2026-90824","https://vuldb.com/submit/914949","https://vuldb.com/vuln/403326","https://vuldb.com/vuln/403326/cti"],"bugs":[""],"patches":{"gpac":[]},"tags":{},"packages":[{"name":"gpac","source":"https://ubuntu.com/security/cve?package=gpac","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=gpac","debian":"https://tracker.debian.org/pkg/gpac","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-90816","published":"2026-09-14T20:17:00","updated_at":"2026-09-17T00:24:09.550325+00:00","description":"\nA vulnerability was found in FFmpeg 8.0.x. This affects the function\nparse_playlist of the file libavformat/hlsproto.c of the component Duration\nParser. Performing a manipulation of the argument duration/target_duration\nresults in denial of service. The attack is possible to be carried out\nremotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue.\nThe patch is named 64fafd63f0b4. Upgrading the affected component is\nrecommended.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90816","https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21492","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/64fafd63f0b4ebf8dbbdbdc2296f21a03548b5fc (n8.1)","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/64fafd63f0b4","https://ffmpeg.org/","https://vuldb.com/cve/CVE-2026-90816","https://vuldb.com/submit/922626","https://vuldb.com/vuln/403318","https://vuldb.com/vuln/403318/cti"],"bugs":[""],"patches":{"ffmpeg":[],"libav":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-90815","published":"2026-09-14T20:17:00","updated_at":"2026-09-17T00:32:48.347347+00:00","description":"\nA vulnerability has been found in FFmpeg up to\n4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function\nsetup_3x3 of the file libavfilter/vf_convolution.c of the component\nConvolution Filter. Such manipulation leads to out-of-bounds read. The\nattack can be executed remotely. The exploit has been disclosed to the\npublic and may be used. Upgrading to version 4.4.7, 5.1.9, 6.1.5, 7.1.4,\n8.0.2, 8.1.1 and 9.0 can resolve this issue. The name of the patch is\n8970658472/e24b9820b4. It is suggested to upgrade the affected component.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.1,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90815","https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21487","https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/8970658472d1","https://ffmpeg.org/","https://vuldb.com/cve/CVE-2026-90815","https://vuldb.com/submit/922609","https://vuldb.com/vuln/403317","https://vuldb.com/vuln/403317/cti"],"bugs":[""],"patches":{"ffmpeg":[],"libav":[]},"tags":{},"packages":[{"name":"ffmpeg","source":"https://ubuntu.com/security/cve?package=ffmpeg","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=ffmpeg","debian":"https://tracker.debian.org/pkg/ffmpeg","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"libav","source":"https://ubuntu.com/security/cve?package=libav","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=libav","debian":"https://tracker.debian.org/pkg/libav","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-54559","published":"2026-09-14T20:16:00","updated_at":"2026-09-16T10:46:49.785839+00:00","description":"\nPocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie\nlanguage-model loaders in src/lm/ngram_model_trie.c do not adequately\nvalidate boundary conditions in ARPA, DMP, and binary format headers, and\nthe acoustic-model loaders in src/mdef.c and src/util/bio.c use sscanf with\nunbounded string fields. Loading an invalid, corrupted, or malicious\nlanguage or acoustic model can therefore cause stack or heap buffer\noverflows and memory corruption. An attacker who can write to a directory\nselected by POCKETSPHINX_PATH can replace or add a model file that\nPocketSphinx later loads; users of PocketSphinx 5prealpha have no\nbackported patch and must migrate to the fixed release. This issue is fixed\nin version 5.1.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-54559","https://github.com/cmusphinx/pocketsphinx/commit/2a3c03788a9973eff548664334fb781e9f4ad4a5","https://github.com/cmusphinx/pocketsphinx/releases/tag/v5.1.1","https://github.com/cmusphinx/pocketsphinx/security/advisories/GHSA-56r5-2p2f-7cxp"],"bugs":[""],"patches":{"pocketsphinx":[]},"tags":{},"packages":[{"name":"pocketsphinx","source":"https://ubuntu.com/security/cve?package=pocketsphinx","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pocketsphinx","debian":"https://tracker.debian.org/pkg/pocketsphinx","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-19816","published":"2026-09-14T20:16:00","updated_at":"2026-09-16T10:35:24.595062+00:00","description":"\nA flaw was found in PackageKit. PackageKit skips the polkit authorization\ncheck for transactions carrying the SIMULATE (dry-run) flag. In the dnf5\nbackend, the RepoRemove handler ignores that contract and always executes\nthe real transaction because its guard is written as (role == REPO_REMOVE\n|| !SIMULATE), which is always true for RepoRemove. An unprivileged local\nuser can therefore perform a genuine package uninstall while claiming to\nsimulate. This vulnerability only affects systems using PackageKit with the\ndnf5 backend.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-19816","https://bugzilla.redhat.com/show_bug.cgi?id=2515940","https://github.com/PackageKit/PackageKit/security/advisories/GHSA-g5gf-h68q-gxc8"],"bugs":[""],"patches":{"packagekit":[]},"tags":{},"packages":[{"name":"packagekit","source":"https://ubuntu.com/security/cve?package=packagekit","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=packagekit","debian":"https://tracker.debian.org/pkg/packagekit","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.4.0-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-19624","published":"2026-09-14T20:16:00","updated_at":"2026-09-16T10:35:33.193781+00:00","description":"\nA flaw was found in NetworkManager-l2tp. The plugin writes\nattacker-controlled VPN connection properties (vpn.data and vpn.secrets\nvalues) unescaped into a generated ipsec.conf file that pluto loads as\nroot. A local unprivileged user can create and activate their own L2TP VPN\nprofile containing a newline-injected leftupdown directive; pluto executes\nthat command as root when the IKE security association is established,\nresulting in local privilege escalation. This is the same bug class as\nCVE-2018-10900 (NetworkManager-vpnc).","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-19624"],"bugs":[""],"patches":{"network-manager-l2tp":[]},"tags":{},"packages":[{"name":"network-manager-l2tp","source":"https://ubuntu.com/security/cve?package=network-manager-l2tp","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=network-manager-l2tp","debian":"https://tracker.debian.org/pkg/network-manager-l2tp","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"1.52.6-1","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-82049","published":"2026-09-14T19:17:00","updated_at":"2026-09-16T11:17:00.404511+00:00","description":"\nIn CPython 3.13 and earlier, the tarfile module's data and tar extraction\nfilters are vulnerable to crafted archives containing a hard link to a\nsymbolic link. Such archives may cause extraction to modify the permissions\nor modification time of a file outside the destination directory, or expose\nthe contents of that file within the extracted tree.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.4,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-82049","https://github.com/python/cpython/issues/157190","https://github.com/python/cpython/pull/157191","https://github.com/python/cpython/pull/157262 (3.15)","https://github.com/python/cpython/pull/157261 (3.14)","https://github.com/python/cpython/pull/157192 (3.13)","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d (3.13 branch)","https://github.com/python/cpython/pull/157454 (3.12)","https://github.com/python/cpython/commit/5a57248b22ad3b9aafcaaadae2c304a1923daeca","https://github.com/python/cpython/commit/b38be2e6cf9d989075ab73412c63e003ebad4ff3","https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d","https://mail.python.org/archives/list/security-announce@python.org/thread/EFJWGAZJA56AKSBR2WHMHQZO7RRLZPRH/","http://www.openwall.com/lists/oss-security/2026/09/14/27"],"bugs":[""],"patches":{"pypy3":[],"python2.7":[],"python3.4":[],"python3.5":[],"python3.6":[],"python3.7":[],"python3.8":[],"python3.9":[],"python3.10":[],"python3.11":[],"python3.12":[],"python3.14":[]},"tags":{},"packages":[{"name":"pypy3","source":"https://ubuntu.com/security/cve?package=pypy3","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pypy3","debian":"https://tracker.debian.org/pkg/pypy3","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python2.7","source":"https://ubuntu.com/security/cve?package=python2.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python2.7","debian":"https://tracker.debian.org/pkg/python2.7","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.4","source":"https://ubuntu.com/security/cve?package=python3.4","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.4","debian":"https://tracker.debian.org/pkg/python3.4","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.5","source":"https://ubuntu.com/security/cve?package=python3.5","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.5","debian":"https://tracker.debian.org/pkg/python3.5","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.6","source":"https://ubuntu.com/security/cve?package=python3.6","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.6","debian":"https://tracker.debian.org/pkg/python3.6","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.7","source":"https://ubuntu.com/security/cve?package=python3.7","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.7","debian":"https://tracker.debian.org/pkg/python3.7","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.8","source":"https://ubuntu.com/security/cve?package=python3.8","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.8","debian":"https://tracker.debian.org/pkg/python3.8","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.9","source":"https://ubuntu.com/security/cve?package=python3.9","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.9","debian":"https://tracker.debian.org/pkg/python3.9","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.10","source":"https://ubuntu.com/security/cve?package=python3.10","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.10","debian":"https://tracker.debian.org/pkg/python3.10","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.11","source":"https://ubuntu.com/security/cve?package=python3.11","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.11","debian":"https://tracker.debian.org/pkg/python3.11","statuses":[{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.12","source":"https://ubuntu.com/security/cve?package=python3.12","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.12","debian":"https://tracker.debian.org/pkg/python3.12","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"python3.14","source":"https://ubuntu.com/security/cve?package=python3.14","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=python3.14","debian":"https://tracker.debian.org/pkg/python3.14","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-82035","published":"2026-09-14T19:17:00","updated_at":"2026-09-16T11:30:57.906934+00:00","description":"\nPyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal\nvulnerability in the font branch of extract_objects() in src/__main__.py,\nwhere the output filename is constructed by joining a document-controlled\nBaseFont name directly onto the user-supplied output directory without\nstripping path separators or dot-dot sequences. Attackers can supply a\ncrafted PDF, EPUB, XPS, or FB2 file with a BaseFont name containing encoded\npath separators that decode to ../ sequences or absolute paths, causing\narbitrary file writes outside the intended output directory without\nrequiring authentication or elevated privileges.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":7.1,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-82035"],"bugs":[""],"patches":{"pymupdf":[]},"tags":{},"packages":[{"name":"pymupdf","source":"https://ubuntu.com/security/cve?package=pymupdf","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=pymupdf","debian":"https://tracker.debian.org/pkg/pymupdf","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55847","published":"2026-09-14T18:17:00","updated_at":"2026-09-16T10:44:04.815461+00:00","description":"\nAllure 2 is the version 2.x branch of Allure Report, a multi-language test\nreporting tool. Prior to 2.39.0, the ansi.js helper at\nallure-generator/src/main/javascript/helpers/ansi.js passes\nattacker-influenced statusMessage and statusTrace values through AnsiToHtml\nwithout HTML escaping and wraps the result in Handlebars SafeString,\ndisabling template auto-escaping in\nallure-generator/src/main/javascript/blocks/status-details/status-details.hbs.\nJunitXmlPlugin.java can populate these fields directly from crafted JUnit\nXML failure messages and traces, and equivalent input flows exist in the\nTRX, xUnit XML, xctest, and Allure1 and Allure2 plugins. When a user views\nthe affected status details, unescaped markup executes arbitrary JavaScript\nin the report origin, which can expose report data and compromise sessions\nassociated with that origin. This is an incomplete-fix case because PR 3271\nescaped link helpers but did not address the ANSI helper. This issue is\nfixed in version 2.39.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55847"],"bugs":[""],"patches":{"allure":[]},"tags":{},"packages":[{"name":"allure","source":"https://ubuntu.com/security/cve?package=allure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=allure","debian":"https://tracker.debian.org/pkg/allure","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55846","published":"2026-09-14T18:17:00","updated_at":"2026-09-16T10:48:20.898233+00:00","description":"\nAllure 2 is the version 2.x branch of Allure Report, a multi-language test\nreporting tool. Prior to 2.39.0, the HTTP server started by allure serve\nand allure open uses URI.getPath() in Commands.setUpServer() in\nallure-commandline/src/main/java/io/qameta/allure/Commands.java and passes\nthe percent-decoded request path to reportDirectory.resolve() without\nnormalizing the result or confirming that it remains inside that directory.\nAn unauthenticated client that can reach the server can submit\nparent-directory segments, including percent-encoded segments, and cause\nserveFile() to return any regular file readable by the Allure process. The\nserver binds to localhost by default, but the --host option can expose it\nto other systems, and local users, adjacent containers, or browser-origin\nattacks may reach a local listener. This can disclose credentials,\nconfiguration, source code, build secrets, and other CI/CD data. This issue\nis fixed in version 2.39.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55846"],"bugs":[""],"patches":{"allure":[]},"tags":{},"packages":[{"name":"allure","source":"https://ubuntu.com/security/cve?package=allure","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=allure","debian":"https://tracker.debian.org/pkg/allure","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53495","published":"2026-09-14T18:17:00","updated_at":"2026-09-16T10:39:57.993148+00:00","description":"\ncontainerd is an open-source container runtime. Prior to 1.7.35, 2.0.12,\n2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can\nindefinitely block the drainExecSyncIO goroutine in\ninternal/cri/server/container_execsync.go when CRI ExecSync is used by exec\nprobes or lifecycle hooks that launch long-lived background child processes\nretaining standard input and output pipes. The input and output drain phase\nhas no default timeout and did not stop when the request context was\ncanceled, so repeated ExecSync invocations can accumulate blocked\ngoroutines and host memory. The resulting resource exhaustion can cause the\nOOM killer to terminate containerd, leaving the container runtime\nunavailable until restart. Deployments not using containerd's CRI\nimplementation and containers not running on Linux are not affected. This\nissue is fixed in versions 1.7.35, 2.0.12, 2.2.8, and 2.3.5.","ubuntu_description":"","notes":[{"author":"alexmurray","note":"Traditionally the containerd source package contained both the\nlibrary and docker application. However, in releases that\ncontain the\ncontainerd-app source package, the containerd source package\ncontains only\nthe library whilst the docker application itself is contained\nin the\ncontainerd-app package."},{"author":"mdeslaur","note":"containerd-app gets new upstream versions, containerd-stable\ngets backported security updates and minor point updates"}],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.8,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53495"],"bugs":[""],"patches":{"containerd":[],"containerd-app":[],"containerd-stable":[]},"tags":{},"packages":[{"name":"containerd","source":"https://ubuntu.com/security/cve?package=containerd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=containerd","debian":"https://tracker.debian.org/pkg/containerd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"containerd-app","source":"https://ubuntu.com/security/cve?package=containerd-app","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=containerd-app","debian":"https://tracker.debian.org/pkg/containerd-app","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]},{"name":"containerd-stable","source":"https://ubuntu.com/security/cve?package=containerd-stable","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=containerd-stable","debian":"https://tracker.debian.org/pkg/containerd-stable","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-90804","published":"2026-09-14T17:17:00","updated_at":"2026-09-17T00:39:41.833080+00:00","description":"\nA vulnerability was detected in GNU Binutils 2.47. Affected by this issue\nis the function _bfd_elf_write_section_eh_frame of the file\nbfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a\nmanipulation of the argument\ncie_length/fde_length/augmentation_data_size/write_offset results in buffer\noverflow. Attacking locally is a requirement. The exploit is now public and\nmay be used. The project was informed of the problem early through a bug\nreport but has not responded yet.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"binutils isn't safe for untrusted inputs."}],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.8,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":0.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90804","https://sourceware.org/bugzilla/show_bug.cgi?id=34445"],"bugs":[""],"patches":{"binutils":[]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-90803","published":"2026-09-14T17:17:00","updated_at":"2026-09-17T00:38:22.792959+00:00","description":"\nA security vulnerability has been detected in GNU Binutils 2.47. Affected\nby this vulnerability is the function elf_x86_64_relocate_section of the\nfile bfd/elf64-x86-64.c of the component ld. Such manipulation of the\nargument roff leads to buffer overflow. An attack has to be approached\nlocally. The exploit has been disclosed publicly and may be used. Upgrading\nto version 2.48 addresses this issue. The name of the patch is\n471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the\naffected component.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"binutils isn't safe for untrusted inputs."}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90803","https://sourceware.org/bugzilla/show_bug.cgi?id=34444"],"bugs":[""],"patches":{"binutils":[]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-90802","published":"2026-09-14T17:17:00","updated_at":"2026-09-17T00:38:02.810702+00:00","description":"\nA weakness has been identified in GNU Binutils 2.47. Affected is the\nfunction bfd_putl64 of the file bfd/libbfd.c of the component ld. This\nmanipulation causes null pointer dereference. The attack requires local\naccess. The exploit has been made available to the public and could be used\nfor attacks. The project was informed of the problem early through a bug\nreport but has not responded yet.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"binutils isn't safe for untrusted inputs."}],"codename":null,"priority":"medium","cvss3":4.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":4.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90802","https://sourceware.org/bugzilla/show_bug.cgi?id=34443"],"bugs":[""],"patches":{"binutils":[]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-90801","published":"2026-09-14T17:17:00","updated_at":"2026-09-17T00:35:45.508305+00:00","description":"\nA security flaw has been discovered in GNU Binutils 2.47. This impacts the\nfunction cache_bwrite of the file bfd/cache.c of the component ld. The\nmanipulation of the argument nbytes results in buffer overflow. The attack\nrequires a local approach. The exploit has been released to the public and\nmay be used for attacks. The project was informed of the problem early\nthrough a bug report but has not responded yet.","ubuntu_description":"","notes":[{"author":"seth-arnold","note":"binutils isn't safe for untrusted inputs."}],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseMetrics":{"exploitabilityMetrics":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":1.9,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90801","https://sourceware.org/bugzilla/show_bug.cgi?id=34442"],"bugs":[""],"patches":{"binutils":[]},"tags":{},"packages":[{"name":"binutils","source":"https://ubuntu.com/security/cve?package=binutils","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=binutils","debian":"https://tracker.debian.org/pkg/binutils","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-84445","published":"2026-09-14T17:17:00","updated_at":"2026-09-16T16:47:44.267048+00:00","description":"\ngRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and\n1.83.2, servers created with xds.NewGRPCServer() allow\ninternal/transport/http2_server.go to accept an RPC containing neither the\n:authority header nor the Host header, while RouteAndProcess in\ninternal/xds/server/routing.go assumes that an authority value exists and\nindexes the empty slice. A remote client that can complete transport\nconnection establishment can trigger an index-out-of-bounds panic that is\nnot recovered by the per-RPC goroutine and terminates the entire server\nprocess. In insecure or ordinary TLS deployments the request can be\nunauthenticated, while strict mTLS or ALTS deployments require valid\ntransport credentials before the malformed RPC can reach the interceptor.\nThis issue is fixed in versions 1.82.2 and 1.83.2.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":null,"impact":{"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":8.7,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-84445"],"bugs":[""],"patches":{"golang-github-googlecloudplatform-grpc-gcp-go":[]},"tags":{},"packages":[{"name":"golang-github-googlecloudplatform-grpc-gcp-go","source":"https://ubuntu.com/security/cve?package=golang-github-googlecloudplatform-grpc-gcp-go","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=golang-github-googlecloudplatform-grpc-gcp-go","debian":"https://tracker.debian.org/pkg/golang-github-googlecloudplatform-grpc-gcp-go","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-55073","published":"2026-09-14T17:17:00","updated_at":"2026-09-16T10:44:53.450238+00:00","description":"\nWeasyPrint helps web developers to create PDF documents. Prior to 70.0,\nserver-side applications that configure a restrictive url_fetcher and pass\nattacker-influenced values to HTML.write_pdf() can have the restriction\nbypassed through the xmp_metadata or stylesheets options. In\nweasyprint/pdf/init.py, xmp_metadata calls select_source() without the\ndocument url_fetcher, allowing an accessible local file to be read and\nembedded verbatim in the output PDF. In weasyprint/document.py, stylesheets\nconstructs CSS() without the document url_fetcher, allowing local or\ninternal resource loading and propagating the permissive fetcher through\nnested CSS imports and url() references. The stylesheets channel applies\nfetched resources but does not by itself disclose stylesheet comments\nverbatim. This issue is fixed in version 70.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.2,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.2,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-55073"],"bugs":[""],"patches":{"weasyprint":[]},"tags":{},"packages":[{"name":"weasyprint","source":"https://ubuntu.com/security/cve?package=weasyprint","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=weasyprint","debian":"https://tracker.debian.org/pkg/weasyprint","statuses":[{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-90996","published":"2026-09-14T16:17:00","updated_at":"2026-09-17T00:22:12.199535+00:00","description":"\nA flaw was found in sssd. A local unprivileged user could send a specially\ncrafted request with a zero-length body to the Network Security Services\n(NSS) responder. This could lead to a denial-of-service condition, causing\nthe NSS responder to become unstable or terminate. This vulnerability\naffects the availability of the system responder.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.0,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90996","https://bugzilla.redhat.com/show_bug.cgi?id=2478986"],"bugs":[""],"patches":{"sssd":[]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-90995","published":"2026-09-14T16:17:00","updated_at":"2026-09-17T00:23:25.822025+00:00","description":"\nA flaw was found in SSSD (System Security Services Daemon). A local\nattacker with privileges to connect to the PAM (Pluggable Authentication\nModules) responder socket can send a specially crafted protocol request. If\nthe `pam_app_services` configuration is enabled and the service item is\nomitted from the request, a NULL pointer dereference can occur. This\nvulnerability leads to a denial of service, causing the PAM responder to\ncrash and disrupt authentication services.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-90995","https://bugzilla.redhat.com/show_bug.cgi?id=2479464"],"bugs":[""],"patches":{"sssd":[]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all§ion=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":780,"limit":20,"total_results":79316}