{"cves":[{"id":"CVE-2026-53877","published":"2026-07-07T15:16:00","updated_at":"2026-07-09T14:47:02.086063+00:00","description":"\nAn issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.\n`django.contrib.gis.gdal.GDALRaster` over-reads its in-memory buffer when\nconstructed from a bytes object, which can disclose adjacent memory or\ncause service degradation via a potential segmentation fault when the\n`vsi_buffer` property is accessed.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were\nnot evaluated and may also be affected.\nDjango would like to thank Bence Nagy for reporting this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":4.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":4.8,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"LOW"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53877","https://www.djangoproject.com/weblog/2026/jul/07/security-releases/"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141629"],"patches":{"python-django":[]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3:5.2.16-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-48588","published":"2026-07-07T15:16:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nAn issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.\n`UpdateCacheMiddleware` and the `cache_page()` decorator cache responses\nthat vary on cookies when the incoming request carries unrelated cookies,\nwhich allows remote attackers to read private data from the shared cache.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were\nnot evaluated and may also be affected.\nDjango would like to thank Chris Whyland for reporting this issue.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":3.1,"baseSeverity":"LOW"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":2.3,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-48588","https://www.djangoproject.com/weblog/2026/jul/07/security-releases/"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141629"],"patches":{"python-django":[]},"tags":{},"packages":[{"name":"python-django","source":"https://ubuntu.com/security/cve?package=python-django","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=python-django","debian":"https://tracker.debian.org/pkg/python-django","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3:5.2.16-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14940","published":"2026-07-07T15:16:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\nA heap-buffer-overflow flaw was found in 389 Directory Server\n(389-ds-base). When\nnormalizing a Distinguished Name (DN) that contains a legacy-quoted value\nencoding a\nmultivalued nested Relative Distinguished Name (RDN), the server can write\npast the\nend of a heap allocation while sorting RDN attribute-value pairs. An\nunauthenticated\nremote attacker can trigger this condition by sending an LDAP operation\nwhose DN\nreaches the DN normalization routine, such as a search with a crafted base\nDN. This\ncan corrupt heap memory and may cause denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14940","https://bugzilla.redhat.com/show_bug.cgi?id=2497697"],"bugs":[""],"patches":{"389-ds-base":[]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2011-10043","published":"2026-07-07T12:16:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\nModule::Load versions before 0.22 for Perl allow arbitrary modules outside\nof @INC to be loaded.\nModule names starting with \"::\" could be passed to the load function to\nspecify arbitrary module paths.\nAttackers able to influence module names passed to load could use that bug\nto execute arbitrary code.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":9.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2011-10043","https://lists.security.metacpan.org/cve-announce/msg/41608305/"],"bugs":[""],"patches":{"perl":[]},"tags":{},"packages":[{"name":"perl","source":"https://ubuntu.com/security/cve?package=perl","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=perl","debian":"https://tracker.debian.org/pkg/perl","statuses":[{"release_codename":"trusty","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"not-affected","description":"5.34.0-3ubuntu1.5","component":null,"pocket":"security"},{"release_codename":"noble","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"not-affected","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"5.18.1-2","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14476","published":"2026-07-07T10:16:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nA path traversal flaw was found in SSSD's AD GPO provider. The\nad_gpo_extract_smb_components() function does not sanitize .. sequences in\nthe gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO\nmanagement access to write files outside the GPO cache directory as root.\nOn default RHEL configurations with SELinux enforcing, this can be used to\ninject Kerberos configuration leading to authentication bypass.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.0,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.0,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14476","https://bugzilla.redhat.com/show_bug.cgi?id=2496581","https://access.redhat.com/security/cve/CVE-2026-14476"],"bugs":[""],"patches":{"sssd":[]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-14474","published":"2026-07-07T10:16:00","updated_at":"2026-07-09T14:45:11.045637+00:00","description":"\nA flaw was found in SSSD's LDAP sudo provider. When the\nldap_sudo_search_base option is not explicitly configured, SSSD searches\nthe entire LDAP directory tree for sudoRole objects. An authenticated\nattacker with write access to any subtree can inject a sudoRole object\ngranting root-level sudo privileges on all SSSD-enrolled hosts.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-14474","https://bugzilla.redhat.com/show_bug.cgi?id=2496556","https://access.redhat.com/security/cve/CVE-2026-14474"],"bugs":[""],"patches":{"sssd":[]},"tags":{},"packages":[{"name":"sssd","source":"https://ubuntu.com/security/cve?package=sssd","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=sssd","debian":"https://tracker.debian.org/pkg/sssd","statuses":[{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-11610","published":"2026-07-07T10:16:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\nA heap buffer overflow flaw was found in the SASL I/O layer of 389\nDirectory Server\n(389-ds-base). After a successful SASL bind with integrity protection (SSF\n> 0),\nan authenticated attacker can send a specially crafted oversized LDAP\nUNBIND packet\nthat is copied into a 512-byte heap receive buffer without a bounds check\nin\nsasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of\nattacker-controlled data to overflow the buffer, causing a denial of\nservice (server\ncrash). In FreeIPA and Red Hat Identity Management deployments, any domain\nuser with\na valid Kerberos ticket, any enrolled host, or any service account can\ntrigger this\nvulnerability over the network after authenticating via GSSAPI.\nThe vulnerable code path has existed since approximately 2013 (389-ds-base\n1.3.2) and\nwas not addressed by the CVE-2025-14905 fix, which patched a separate heap\noverflow\nin schema.c only.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":8.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-11610","https://bugzilla.redhat.com/show_bug.cgi?id=2484414","https://access.redhat.com/security/cve/CVE-2026-11610"],"bugs":[""],"patches":{"389-ds-base":[]},"tags":{},"packages":[{"name":"389-ds-base","source":"https://ubuntu.com/security/cve?package=389-ds-base","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=389-ds-base","debian":"https://tracker.debian.org/pkg/389-ds-base","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-58384","published":"2026-07-07T09:16:00","updated_at":"2026-07-09T14:46:28.887269+00:00","description":"\nA flaw was found in GIMP's PSD parser. An integer overflow in\nread_RLE_channel() can cause an undersized heap allocation for the RLE\nrow-length table, after which subsequent per-row writes corrupt heap\nmemory. This could lead to memory corruption, potentially resulting in\ndenial of service or arbitrary code execution.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":7.3,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.3,"baseSeverity":"HIGH"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58384","https://gitlab.gnome.org/GNOME/gimp/-/work_items/16216","https://access.redhat.com/security/cve/CVE-2026-58384","https://bugzilla.redhat.com/show_bug.cgi?id=2497431","https://gitlab.gnome.org/GNOME/gimp/-/commit/da29e217","https://gitlab.gnome.org/GNOME/gimp/-/issues/16216"],"bugs":[""],"patches":{"gimp":[]},"tags":{},"packages":[{"name":"gimp","source":"https://ubuntu.com/security/cve?package=gimp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gimp","debian":"https://tracker.debian.org/pkg/gimp","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"3.2.4-1","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50135","published":"2026-07-06T21:16:00","updated_at":"2026-07-09T15:14:49.465585+00:00","description":"\nHugo is a static site generator. From 0.123.0 to 0.161.1, a regression made\n RootMappingFs.statRoot  use  Stat  (follows symlinks) instead of  Lstat ,\nso a direct  resources.Get  of a symlink pointing outside its mount\nreturned the target's contents — letting a symlink planted in a local mount\n(e.g. a vendored  themes/  theme) read arbitrary files accessible to the\nHugo user. Go-module themes from GitHub (symlinks stripped) and directory\nwalks were unaffected. Fixed in 0.162.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50135","https://github.com/gohugoio/hugo/security/advisories/GHSA-fw87-fv5r-9fpw","https://github.com/gohugoio/hugo/commit/f8b5fa09a64950c32b803821ede411ebfe772b7a","https://github.com/gohugoio/hugo/releases/tag/v0.162.0"],"bugs":[""],"patches":{"hugo":[]},"tags":{},"packages":[{"name":"hugo","source":"https://ubuntu.com/security/cve?package=hugo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hugo","debian":"https://tracker.debian.org/pkg/hugo","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.162.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-59089","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:46:28.887269+00:00","description":"\nA flaw was found in GIMP. The PlayStation TIM loader, responsible for\nhandling PlayStation image files, incorrectly calculates the size of the\nColor Look-Up Table (CLUT) due to an integer overflow. This occurs when\nmultiplying num_colors and num_cluts, both 16-bit unsigned short integers,\nresulting in a value exceeding the maximum integer limit. An attacker could\nexploit this by providing a specially crafted image file, leading to\nundefined behavior and causing the GIMP plug-in to abort, effectively\nresulting in a denial of service.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-59089","https://gitlab.gnome.org/GNOME/gimp/-/work_items/16493","https://access.redhat.com/security/cve/CVE-2026-59089","https://bugzilla.redhat.com/show_bug.cgi?id=2496583"],"bugs":[""],"patches":{"gimp":[]},"tags":{},"packages":[{"name":"gimp","source":"https://ubuntu.com/security/cve?package=gimp","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=gimp","debian":"https://tracker.debian.org/pkg/gimp","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-58404","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:46:28.887269+00:00","description":"\nHugo is a static site generator. From v0.162.0 through v0.163.0, the\ndefault security.http.urls policy denies requests to loopback, internal,\nand cloud-metadata IPv4 literals, but the deny rule only matched\ndotted-decimal notation, so alternate IPv4 encodings of the same addresses,\nincluding integer, hex, or octal, passed the policy. When a template passes\nan untrusted or data-derived URL to resources.GetRemote and the host\nplatform uses the cgo system resolver, these encodings resolve to the\nblocked address, allowing build-time server-side requests to loopback and\ninternal services, including the cloud-metadata endpoint in hosted or CI\nbuilds; the same check is reused on redirects, so the gap also applies to\neach redirect hop. This issue is fixed in v0.163.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.8,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":4.6,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58404","https://github.com/gohugoio/hugo/security/advisories/GHSA-r46f-3rpw-hxrv","https://github.com/gohugoio/hugo/pull/15020","https://github.com/gohugoio/hugo/commit/a00b5c72ac57afe26df6688ece3ca544a56df372","https://github.com/gohugoio/hugo/releases/tag/v0.163.1"],"bugs":[""],"patches":{"hugo":[]},"tags":{},"packages":[{"name":"hugo","source":"https://ubuntu.com/security/cve?package=hugo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hugo","debian":"https://tracker.debian.org/pkg/hugo","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-58403","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:46:28.887269+00:00","description":"\nHugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's\nvirtual filesystem is designed so that files under a mount cannot reach\noutside the mount tree, but a regression caused RootMappingFs.statRoot to\ncall Stat, which follows symlinks, instead of Lstat, so a direct\nos.ReadFile \"somefile\" where somefile was a symlink pointing outside the\nmount would return the target's contents. This effectively let a symlink\nplanted inside a theme or local mount read arbitrary files reachable to the\nuser running hugo. This issue is fixed in v0.163.1.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":5.9,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58403","https://github.com/gohugoio/hugo/security/advisories/GHSA-c3wq-j5vh-68rc","https://github.com/gohugoio/hugo/pull/15020","https://github.com/gohugoio/hugo/commit/cf9c8f93ca2a2838ce378f9e36d052ac2f79e229","https://github.com/gohugoio/hugo/releases/tag/v0.163.1"],"bugs":[""],"patches":{"hugo":[]},"tags":{},"packages":[{"name":"hugo","source":"https://ubuntu.com/security/cve?package=hugo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hugo","debian":"https://tracker.debian.org/pkg/hugo","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-58402","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:46:00.512887+00:00","description":"\nHugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default\ncode-block renderer wrote the Markdown code-fence language or info-string\ninto the code class=\"language-…\" data-lang=\"…\" wrapper without HTML\nescaping. A fence info-string containing a quote and a script payload\nbreaks out of the attribute and injects a live script element. This issue\nis fixed in 0.163.3.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.4,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"LOW","userInteraction":"PASSIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":5.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-58402","https://github.com/gohugoio/hugo/security/advisories/GHSA-q76j-gcg9-vxc6","https://github.com/gohugoio/hugo/pull/15051","https://github.com/gohugoio/hugo/commit/ce1a7e0bce3713af40496ded3c2c0ceeed49231d","https://github.com/gohugoio/hugo/releases/tag/v0.163.3"],"bugs":[""],"patches":{"hugo":[]},"tags":{},"packages":[{"name":"hugo","source":"https://ubuntu.com/security/cve?package=hugo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hugo","debian":"https://tracker.debian.org/pkg/hugo","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-53763","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:46:00.512887+00:00","description":"\nOP-TEE is a Trusted Execution Environment (TEE) designed as companion to a\nnon-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone\ntechnology. Starting in version 3.0.0 and prior to version 4.11.0, 32-bit\ninteger overflows in OP-TEE core's AES-GCM implementation cause the\nauthentication tag to be computed with incorrect bit-length values after\nprocessing more than 512 megabytes of payload or Additional Authenticated\nData (AAD). Version 4.11.0 contains a patch. No known workarounds are\navailable.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":3.8,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-53763","https://github.com/OP-TEE/optee_os/security/advisories/GHSA-fcm8-vjhf-6vqh"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141642"],"patches":{"optee-os":[]},"tags":{},"packages":[{"name":"optee-os","source":"https://ubuntu.com/security/cve?package=optee-os","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=optee-os","debian":"https://tracker.debian.org/pkg/optee-os","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50134","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nHugo is a static site generator. From 0.91.0 until 0.162.0,\nresources.GetRemote enforces security.http.urls on the URL it is called\nwith, but it did not re-validate intermediate URLs on HTTP 3xx redirects.\nAn allowed server (or an attacker controlling its DNS or response) could\ntherefore redirect the request to a host that the policy was meant to\nforbid and Hugo would fetch from the redirected target. The same bypass\nalso lifted any host-shape restriction the operator had put in place. This\nvulnerability is fixed in 0.162.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5.8,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"NONE","userInteraction":"NONE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},"baseScore":6.3,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50134","https://github.com/gohugoio/hugo/security/advisories/GHSA-vxgm-5rmg-5w8g","https://github.com/gohugoio/hugo/commit/86fbb0f7a8bbb93e2e916390de9e5a4f24bf9f50","https://github.com/gohugoio/hugo/releases/tag/v0.162.0"],"bugs":[""],"patches":{"hugo":[]},"tags":{},"packages":[{"name":"hugo","source":"https://ubuntu.com/security/cve?package=hugo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hugo","debian":"https://tracker.debian.org/pkg/hugo","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.162.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-50133","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\nHugo is a static site generator. Prior to 0.162.0, Hugo accepts content\nfiles in several markup formats. Files mapped to the text/html media type\n(typically .html files under /content, or pages produced by a content\nadapter that sets content.mediaType = \"text/html\") had their body emitted\nverbatim into the rendered page. A site that ingests HTML content from an\nuntrusted source could therefore be served stored cross-site scripting.\nThis vulnerability is fixed in 0.162.0.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":6.1,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM"}},"baseMetricV4":{"cvssV4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","baseMetrics":{"exploitabilityMetrics":{"attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"ACTIVE"},"vulnerableSystemImpactMetrics":{"confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"NONE"},"subsequentSystemImpactMetrics":{"confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},"baseScore":5.1,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-50133","https://github.com/gohugoio/hugo/security/advisories/GHSA-c54g-xjwj-8g82","https://github.com/gohugoio/hugo/commit/e41a06447daa3071a01f333fdcec0a5153c3c8d1","https://github.com/gohugoio/hugo/releases/tag/v0.162.0"],"bugs":[""],"patches":{"hugo":[]},"tags":{},"packages":[{"name":"hugo","source":"https://ubuntu.com/security/cve?package=hugo","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=hugo","debian":"https://tracker.debian.org/pkg/hugo","statuses":[{"release_codename":"bionic","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"focal","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"jammy","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"released","description":"0.162.1-1","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"},{"release_codename":"xenial","status":"needs-triage","description":"","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-44362","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:44:41.601638+00:00","description":"\nOP-TEE is a Trusted Execution Environment (TEE) designed as companion to a\nnon-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone\ntechnology. Starting in version 3.20.0 and prior to version 4.11.0, a\nvulnerability in OP-TEE’s subkey rollback protection allows the use of\nrevoked or older subkey versions because the system fails to propagate\nversioning data during the Trusted Application (TA) loading process. In\n`core/crypto/signed_hdr.c`, the function `shdr_load_pub_key()` parses\nsubkey headers but does not assign the `subkey_version` to the runtime\n`shdr_pub_key` structure. As a result, the `key->version` field remains at\nzero regardless of the version specified in the header. When\n`ree_fs_ta_open()` in `core/kernel/ree_fs_ta.c` calls\n`check_update_version()`, it passes this zeroed version to the rollback\ndatabase. Because the database never receives a non-zero version to record,\nit never advances, effectively bypassing the rollback check and allowing\nTAs signed with downgraded subkey chains to load successfully. This impacts\nOP-TEE mainline configurations that utilize subkey-based signing chains for\nTrusted Application (TA) authentication. Version 4.11.0 contains a patch.\nNo known workarounds are available.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":5.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":5.5,"baseSeverity":"MEDIUM"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-44362","https://github.com/OP-TEE/optee_os/security/advisories/GHSA-fhcg-pp56-8v75"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141642"],"patches":{"optee-os":[]},"tags":{},"packages":[{"name":"optee-os","source":"https://ubuntu.com/security/cve?package=optee-os","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=optee-os","debian":"https://tracker.debian.org/pkg/optee-os","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-42546","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\nOP-TEE is a Trusted Execution Environment (TEE) designed as companion to a\nnon-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone\ntechnology. Starting in version 3.3.0 and prior to version 4.11.0, a\nresource leak exists in OP-TEE’s shared memory cleanup logic because the\nfunction `cleanup_shm_refs()` in `core/tee/entry_std.c`  fails to apply a\nrequired bitmask (`OPTEE_MSG_ATTR_TYPE_MASK`) to parameter attributes. When\nprocessing non-contiguous memory parameters from a normal-world caller, the\nsystem fails to match the attribute type in its internal switch statement\nand skips the necessary mobj_put() call. This results in a persistent\nreference leak of `mobj_reg_shm` objects, which remain on internal lists\nwith dangling refcounts. This affects non-FF-A configurations that support\nnon-contiguous, non-secure shared memory. Over time, these accumulated\nleaks progressively consume the secure-world heap, degrading the system's\nability to service trusted application operations and eventually requiring\na reboot to recover. Version 4.11.0 contains a patch. No known workarounds\nare available.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":3.8,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"LOW","baseScore":3.8,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-42546","https://github.com/OP-TEE/optee_os/security/advisories/GHSA-c7j8-fgqw-rcgp"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141642"],"patches":{"optee-os":[]},"tags":{},"packages":[{"name":"optee-os","source":"https://ubuntu.com/security/cve?package=optee-os","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=optee-os","debian":"https://tracker.debian.org/pkg/optee-os","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41516","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:43:57.116024+00:00","description":"\nOP-TEE is a Trusted Execution Environment (TEE) designed as companion to a\nnon-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone\ntechnology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA\nPKCS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driver\nuses non-constant-time `memcmp()` for label hash verification and has\nmultiple distinguishable error paths. This creates a Bleichenbacher-style\npadding oracle that allows an attacker to recover RSA PKCS#1 v1.5\nplaintext. Version 4.11.0 contains a patch. As a workaround, disable\nHisilicon HPRE RSA driver with `CFG_HISILICON_ACC_V3=n`.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41516","https://github.com/OP-TEE/optee_os/security/advisories/GHSA-wxp6-8wwr-h4gf"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141642"],"patches":{"optee-os":[]},"tags":{},"packages":[{"name":"optee-os","source":"https://ubuntu.com/security/cve?package=optee-os","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=optee-os","debian":"https://tracker.debian.org/pkg/optee-os","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]},{"id":"CVE-2026-41515","published":"2026-07-06T20:16:00","updated_at":"2026-07-09T14:44:17.158544+00:00","description":"\nOP-TEE is a Trusted Execution Environment (TEE) designed as companion to a\nnon-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone\ntechnology. Starting in version 3.9.0 and prior to version 4.11.0, the\nRSA-OAEP decryption implementation in the NXP CAAM crypto driver uses\nnon-constant-time `memcmp()` for label hash verification and has multiple\ndistinguishable error paths. This creates a Manger-style padding oracle\nthat allows an attacker to recover RSA-OAEP plaintext with approximately\n1000-2000 adaptive chosen ciphertext queries. Version 4.11.0 contains a\npatch. As a workaround, disable the NXP CAAM RSA driver with\n`CFG_CRYPTO_DRV_RSA=n`.","ubuntu_description":"","notes":[],"codename":null,"priority":"medium","cvss3":2.5,"impact":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.5,"baseSeverity":"LOW"}}},"status":"active","mitigation":"","references":["https://www.cve.org/CVERecord?id=CVE-2026-41515","https://github.com/OP-TEE/optee_os/security/advisories/GHSA-5q45-58r5-cq4g"],"bugs":["http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1141642"],"patches":{"optee-os":[]},"tags":{},"packages":[{"name":"optee-os","source":"https://ubuntu.com/security/cve?package=optee-os","ubuntu":"https://packages.ubuntu.com/search?suite=all&section=all&arch=any&searchon=sourcenames&keywords=optee-os","debian":"https://tracker.debian.org/pkg/optee-os","statuses":[{"release_codename":"jammy","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"noble","status":"DNE","description":"","component":null,"pocket":"security"},{"release_codename":"resolute","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"upstream","status":"needs-triage","description":"","component":null,"pocket":"security"},{"release_codename":"questing","status":"ignored","description":"end of life, was needs-triage","component":null,"pocket":"security"}]}],"notices_ids":[],"notices":[]}],"offset":7980,"limit":20,"total_results":79316}